Scan results

    OP-mobile

    Android

    OP-mobile is a secure banking and insurance management app from OP Pohjola. Manage accounts, confirm payments, use Mobile Key for identification, and access digital services. Supports company banking and location-based ATM/branch finding.

    CITT SCORE
    50
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: OP bank customers comfortable with analytics

    Not For: You share devices with others

    What It Means For You

    User activity is tracked by Firebase and Adobe Marketing Cloud. Multiple high-severity findings were identified in how financial data is stored and transmitted, which may leave banking information less protected than expected. Device details and usage patterns are shared with several third-party services.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (24)

    Data Security

    5 total
    4 High
    1 Medium

    Network Security

    2 total
    1 Critical
    1 Medium

    Code Security

    8 total
    1 Critical
    2 High
    1 Medium
    1 Low
    3 Info

    Privacy

    5 total
    2 High
    3 Medium

    Third-Party Risk

    3 total
    1 Critical
    2 High

    Permission Usage

    1 total
    1 Medium

    Third-Party Services

    Callsign, Firebase, Adobe Marketing Cloud, Google Maps, Samsung Pay, Bouncy Castle, Jackson, Kryo, OkHttp, VASCO

    Security Strengths

    • Hardware-backed encryption (Android KeyStore with TEE/StrongBox)
    • SSL error handling correctly rejects invalid certificates
    • Android backup disabled prevents ADB extraction
    • Strong file access restrictions on insurance WebViews
    • PSD2 SCA compliance via Callsign behavioral biometrics
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    location
    camera
    contacts
    behavioral biometrics
    marketing analytics
    banking

    Package

    fi.op.android.opmobiili

    Version

    79.0.1 (versionCode: 7905)

    Analysis Date

    Jan 31, 2026

    Classes Analyzed

    25,933

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 5 findings (4 high, 1 medium)

    Network Security - 2 findings (1 critical, 1 medium)

    Code Safety - 0 findings

    Privacy - 5 findings (2 high, 3 medium)

    Privacy Concerns

    What Data is Collected

    The app collects device identifiers, location data, and behavioral data including user in-app actions, transaction patterns, and usage frequency. This information supports analytics and personalization features within the app.

    Third-Party Data Sharing

    Data is shared with the following third-party services:

    • Firebase - Analytics and crash reporting
    • Adobe Marketing Cloud - Marketing analytics and behavioral profiling
    • Google Maps - Location and mapping services
    • Samsung Pay - Payment processing
    • Callsign - Identity and authentication services
    • Bouncy Castle - Security library
    • Jackson - Data processing library
    • Kryo - Data processing library
    • OkHttp - Network communications library
    • VASCO - Authentication services

    Understanding the Scores

    CategoryScore
    Security45/100
    Privacy55/100
    Data Security50/100
    Network Security60/100
    Code Safety40/100
    Data Collection70/100
    Data Sharing65/100
    User Control50/100

    Positive Security Features

    • None identified in this version of the app.

    Areas for Improvement

    • Financial data stored on the device may benefit from stronger protection to reduce risk to banking information.
    • Communications between the app and banking servers travel with less protection than expected, which is relevant on public Wi-Fi.
    • The app's underlying code practices need strengthening to reduce the risk of unauthorized access to account information.

    About This Analysis

    This scorecard is generated from automated static analysis of the app's code and behavior patterns. Scores are on a 0-100 scale where higher is better.

    App Details

    • App: OP-mobile
    • Package: fi.op.android.opmobiili
    • Version: 79.0.1 (build 7905)
    • Scan Date: 2026-01-31

    Right of Reply

    Developer not yet contacted