Scan results

    OTP Mobile Banking Moldova

    iOS

    OTP Direkt is a mobile banking authentication app for MobiasBanca that uses biometric authentication and mobile token generation for secure banking operations. The app integrates with iOS Wallet and supports Internet Banking migration flows.

    CITT SCORE
    56
    out of 100
    TRUSTish

    Quick Verdict

    Best for: OTP Direkt customers managing accounts on mobile

    Not For: Users on shared or family devices who stay logged in

    What It Means For You

    Connections to the bank's servers are well protected and user data is not shared with advertisers. Some concerns exist around how account information is safeguarded while stored on the device itself. The app uses Firebase for push notifications and Google Maps for branch locations, but collects minimal personal data beyond what banking requires.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (6)

    Data Security

    2 total
    1 High
    1 Medium

    Code Security

    2 total
    1 Medium
    1 Low

    Privacy

    2 total
    2 Medium

    Third-Party Services

    Firebase Cloud Messaging, PowerAuth2, WultraMobileTokenSDK, Google Maps, Capacitor

    Security Strengths

    • Certificate pinning properly implemented
    • iOS Keychain for mobile token storage
    • Biometric authentication implemented
    • No server-side secrets in client code
    • No App Transport Security exceptions
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    banking
    sensitive data
    biometric auth
    location
    contacts
    camera

    Package

    md.mobiasbanca.otpdirekt

    Version

    3.1.10 (Build 30110)

    Analysis Date

    Mar 27, 2026

    Classes Analyzed

    44

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on App Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 2 findings (1 high, 1 medium)

    Network Security - 0 findings

    Code Safety - 0 findings

    Privacy - 2 findings (2 medium)

    Privacy Concerns

    What Data is Collected

    The app collects the account and transaction information required for banking services. Data collection is limited to what is necessary for the app to function. Location data may be accessed when users use the branch and ATM locator feature powered by Google Maps.

    Third-Party Data Sharing

    User personal data is not shared with advertising or marketing companies. Firebase Cloud Messaging is used to deliver push notifications from the bank to the device. Google Maps is used solely to display branch and ATM locations. The authentication framework used for secure login does not share user personal data with third parties for commercial purposes.

    Understanding the Scores

    CategoryScore
    Security64/100
    Privacy52/100
    Data Security48/100
    Network Security100/100
    Code Safety85/100
    Data Collection97/100
    Data Sharing100/100
    User Control92/100

    Positive Security Features

    • All communication between the app and the bank's servers is fully protected during transmission
    • User data is not shared with advertisers or marketing companies
    • The app collects only what is necessary to provide banking services
    • Strong user controls are in place for managing accounts and app settings

    Areas for Improvement

    • Account information stored locally on the device could benefit from stronger protection, particularly if the phone is lost or stolen
    • Local data storage practices could be hardened to better protect users who share devices or remain logged in
    • Additional safeguards around locally cached account data would improve security for all users

    About This Analysis

    This scorecard is based on static analysis of the app's code and behavior patterns. Scores reflect the app's practices at the time of analysis and may change with future updates.

    App Details

    • App: md.mobiasbanca.otpdirekt
    • Version: 3.1.10 (Build 30110)
    • Scan Date: 2026-03-27
    • Platform: Android

    Right of Reply

    Developer not yet contacted