The White House Security & Privacy Scorecard
by The Official White House · Android
Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.
Best for
General use with standard privacy expectations
Findings
- 0 critical
- 0 high
- 0 medium
- 2 low
- 10 info
1 issue identified across security and privacy analysis.
Top security issues
- RNCWebView Message Bridge Registered with Wildcard Origin
- RNCWebViewFileProvider Configured with Overly Broad External Storage Path
- React Native New Architecture Eliminates Legacy Bridge Attack Surface
Top privacy issues
- OneSignal Push SDK Transmits Device Metadata to Third Party
- No Advertising ID Collection or Cross-App Tracking
- Minimal Android Permission Set
Full analysis
<!-- TRUSTEDVERDICTHEADER -->
TRUSTED
This app passed our trust standard.
Trust Pillars
- Secure by Design: Strong. Meets a high bar in this area.
- Data Respect: Strong. Meets a high bar in this area.
- Honest Experience: Strong. Meets a high bar in this area.
- User Control: Strong. Meets a high bar in this area.
- Child-Safe: Not applicable. Does not apply to this app.
<!-- /TRUSTEDVERDICTHEADER -->
Security & Privacy Scorecard
gov.whitehouse.app
What This Means for You
Usage data and device activity may be shared with the app developer and the services it integrates with. The category summary below shows the scope so people can decide whether it fits their needs.
Recommendation: Very Secure
This app follows strong security and privacy practices.
Best For: Users wanting official White House news and updates who are comfortable with OneSignal push notification data sharing
Avoid If: Users requiring zero third-party data sharing from a government-operated app
Key Findings
Data Security: 2 findings (2 info)
Network Security: 1 finding (1 info)
Code Safety: 0 findings
Privacy: 1 finding (1 info)
Privacy Concerns
What Data is Collected
Review the app's store listing and in-app privacy notices for a full data collection disclosure.
Third-Party Data Sharing
The following third parties may receive user data:
- OneSignal
- Firebase Messaging (FCM transport only)
- ML Kit Barcode Scanner
- Apollo GraphQL
- Expo Modules
- OkHttp3
- React Native WebView
- Glide
- Coil3
- AndroidX Room
- Media3 / ExoPlayer
- AndroidX WorkManager
- AndroidX Browser
- PairIP LicenseCheck
- React Native Reanimated
- React Native Gesture Handler
Understanding the Scores
Security: 99/100
Privacy: 100/100
Security Breakdown
- Data Security: 100/100. How the app handles stored data.
- Network Security: 100/100. How the app handles data in transit.
- Code Safety: 99/100. Overall code hygiene signals.
Privacy Breakdown
- Data Collection: 100/100. Scope of data collected.
- Data Sharing: 100/100. Third-party data sharing behavior.
- User Control: 100/100. Controls the app offers over personal data.
Positive Security Features
- Credentials protected by hardware-backed AES-256-GCM encryption via Android Keystore
- Credentials correctly excluded from cloud backup and device transfer across all API levels
- No analytics, attribution, or advertising SDKs present
- No advertising ID (GAID) collection or cross-app tracking
- Only minimal permissions required — no location, camera, microphone, contacts, or storage access
- All HTTP traffic blocked by OS default at targetSdk 36 with no cleartext exceptions
- WebView file system access fully disabled; SSL errors handled securely with no handler.proceed() bypass
- React Native New Architecture eliminates legacy JSON bridge attack surface
- Zero VulnFanatic findings across all 13 native binaries including Hermes and React Native framework
Areas for Improvement
- Review the category summary above for where the app could strengthen its practices.
- Keep the app updated to receive the latest security improvements from the developer.
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.
App Details
Developer: Unknown developer
Version: 47.0.1 (build) / 47.5.2 (Play Store)
Analysis Date: 2026-07-11
Package: gov.whitehouse.app
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #5 (current) | 99/100 | |
| #4 | 91/100 | |
| #2 | 76/100 | |
| #1 | 74/100 |