Scan results

    Monzo - Mobile Banking

    iOS

    Monzo is a UK fintech bank offering digital banking, payments, expense tracking, and card management with biometric authentication. Version 7.20.0.

    CITT SCORE
    86
    out of 100
    TRUSTED

    Quick Verdict

    Best for: Managing finances with strong security standards

    What It Means For You

    In-app activity and usage patterns are shared with marketing services including Adjust and Braze, which can use this data to send targeted messages. Signing in with Facebook links activity across both platforms. Identity verification steps require submitting personal documents to a third-party service.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (23)

    Data Security

    5 total
    1 Medium
    3 Low
    1 Info

    Network Security

    4 total
    1 Medium
    1 Low
    2 Info

    Code Security

    5 total
    2 Low
    3 Info

    Privacy

    6 total
    1 Medium
    1 Low
    4 Info

    Third-Party Risk

    3 total
    1 Medium
    1 Low
    1 Info

    Third-Party Services

    Adjust (AdjustSigSdk), Sentry, Lottie, Veriff, Plaid (LinkKit), Stripe Terminal, Braze (BrazeKit), PinwheelSDK, AWS Amplify (Cognito), AWS AmplifyUILiveness, Firebase (Core, Installations), AppLab Analytics, AppAuth, Google Maps, Google Sign-In (GTMAppAuth), Realm (MongoDB), GRDB, Alamofire, JOSESwift, SDWebImage, BKMoneyKit, NYTPhotoViewer, Down, Facebook (OAuth)

    Security Strengths

    • Certificate pinning implemented via SecTrustSetAnchorCertificates — full custom trust anchor replacing system CA store, combined with App Attest
    • Biometric-protected keychain with SecAccessControl and Secure Enclave-backed keys for authentication credentials
    • App Lock gates all deep link processing — payment execution cannot be triggered via deep link on locked device
    • ATT consent architecture is comprehensive — multi-layer state machine with persistent user-facing consent management UI
    • Firebase Analytics explicitly disabled across six independent configuration keys — Firebase used only for push notifications
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    location
    biometric

    Package

    io.b2a.BankProd

    Version

    7.20.0 (Build 7200052)

    Analysis Date

    Apr 8, 2026

    0

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on App Store

    Recommendation: Trustworthy

    Key Findings

    Data Security - 5 findings (1 medium, 3 low, 1 info)

    Network Security - 4 findings (1 medium, 1 low, 2 info)

    Code Safety - 0 findings

    Privacy - 6 findings (1 medium, 1 low, 4 info)

    Privacy Concerns

    What Data is Collected

    This app collects account activity, transaction history, and usage patterns. Identity verification requires submitting government-issued documents and biometric data through Veriff. Financial account linking through Plaid may access account balances and transaction records from connected banks. Diagnostic data is collected automatically to monitor app stability.

    Third-Party Data Sharing

    User data is shared with the following third-party services:

    • Adjust - Receives in-app actions and usage patterns for marketing measurement
    • Braze - Receives behavioral data to power targeted push notifications and in-app messages
    • Facebook - Receives activity data when users use Facebook sign-in
    • Veriff - Receives identity documents and biometric data for identity verification
    • Plaid - Receives banking access information to link external financial accounts
    • Stripe Terminal - Receives payment transaction data for payment processing
    • Sentry - Receives diagnostic and error data to improve app stability
    • Firebase - Receives usage analytics and app performance data
    • Google - Provides mapping features and optional sign-in
    • AWS - Provides backend infrastructure and liveness detection for identity flows

    Understanding the Scores

    CategoryScore
    Security87/100
    Privacy86/100
    Data Security88/100
    Network Security93/100
    Code Safety95/100
    Data Collection88/100
    Data Sharing88/100
    User Control93/100

    Positive Security Features

    • Code safety scored 95 out of 100, reflecting well-structured and hardened code across the app
    • Network security scored 93 out of 100, indicating strong protections for data sent between the device and servers
    • User control scored 93 out of 100, reflecting meaningful options for managing account and data
    • Data security scored 88 out of 100, showing solid practices for handling stored information

    Areas for Improvement

    • The number of marketing and analytics services with access to behavioral data could be reduced to limit profiling of in-app habits
    • Third-party identity verification means personal documents and biometric data are handled outside the app's direct control
    • Linking external bank accounts through Plaid introduces an additional third party that receives financial account information

    About This Analysis

    This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect security and privacy practices observed at the time of the scan and may not capture every aspect of how the app handles user data at runtime.

    App Details

    FieldValue
    Packageio.b2a.BankProd
    Version7.20.0 (Build 7200052)
    Scan Date2026-04-08

    Right of Reply

    Developer not yet contacted