Scan results

    Smart M-Air

    Android

    Smart M-Air is a remote control application for Mitsubishi Heavy Industries air conditioning systems. Control your home or office AC units remotely from your smartphone or tablet via WiFi and cloud connectivity. Requires compatible AC unit with wireless interface module.

    CITT SCORE
    52
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Smart M-Air device owners needing remote control

    Not For: You rely on the app over untrusted public Wi-Fi

    What It Means For You

    Usage data is shared with Firebase and Google services for push notifications and analytics. Network communication sends data with less protection than expected, which may affect users on public Wi-Fi. Data stored on the device is encrypted, but permission access to device features warrants review before granting.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (13)

    Data Security

    3 total
    1 High
    1 Medium
    1 Low

    Network Security

    5 total
    1 Critical
    2 High
    1 Medium
    1 Low

    Code Security

    2 total
    1 Medium
    1 Low

    Privacy

    2 total
    1 Medium
    1 Low

    Permission Usage

    1 total
    1 Medium

    Third-Party Services

    AWS Mobile SDK / AWSMobileClient, Firebase Cloud Messaging, Firebase Core/Common, Google Play Services (GMS), OkHttp3, RxJava2, Room (AndroidX), SQLCipher, MPAndroidChart, EventBus (GreenRobot), Jackson (FasterXML)

    Security Strengths

    • Cloud API uses Amazon root CA certificate pinning (5 Amazon root CAs bundled)
    • Android backup explicitly disabled (android:allowBackup=false)
    • AWS Cognito SDK stores session tokens using hardware-backed Android Keystore (AES/GCM)
    • WebView loads only local assets with JavaScript disabled — zero WebView attack surface
    • No analytics, advertising, or session recording SDKs present
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    iot
    home automation
    sensitive data
    location
    network security

    Package

    jp.co.mhi_mth.smartmair

    Version

    1.4.003 (versionCode 34)

    Analysis Date

    Feb 18, 2026

    Classes Analyzed

    8,354

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 3 findings (1 high, 1 medium, 1 low)

    Network Security - 5 findings (1 critical, 2 high, 1 medium, 1 low)

    Code Safety - 0 findings

    Privacy - 2 findings (1 medium, 1 low)

    Privacy Concerns

    What Data is Collected

    The app collects device identifiers and usage activity to support its remote control features. Firebase services record how users interact with the app, including session patterns and feature usage. Google Play Services access device information to deliver notifications about the connected device.

    Third-Party Data Sharing

    User data is shared with these third-party services:

    • Firebase Cloud Messaging - Delivers push notifications to the device
    • Firebase Core/Common - Collects usage and session analytics
    • Google Play Services (GMS) - Supports device notifications and identification
    • AWS Mobile SDK - Handles communication with the app's cloud backend

    Understanding the Scores

    CategoryScore
    Security42/100
    Privacy62/100
    Data Security48/100
    Network Security32/100
    Code Safety68/100
    Data Collection72/100
    Data Sharing82/100
    User Control78/100

    Positive Security Features

    • Local data storage is protected with encryption
    • Third-party integrations are focused on core app functionality rather than broad data gathering
    • User control settings are available within the app

    Areas for Improvement

    • Network connections between the device and the app's cloud services send data with less protection than expected. On public or shared Wi-Fi, commands and device status may be visible to others on the same network.
    • The app requests access to device features beyond what its core remote control function requires. Users should review each permission carefully and only grant those necessary for their use.
    • Third-party analytics services receive data about how users interact with the app. The scope of this collection could be reduced without affecting the core remote control experience.

    About This Analysis

    App Details

    FieldValue
    App NameSmart M-Air
    Packagejp.co.mhi_mth.smartmair
    Version1.4.003 (build 34)
    Scan Date2026-02-18
    Developer-

    Right of Reply

    Developer not yet contacted