OTP Direkt is a mobile banking authentication app for MobiasBanca that uses biometric authentication and mobile token generation for secure banking operations. The app integrates with iOS Wallet and supports Internet Banking migration flows.
Quick Verdict
Best for: OTP Direkt customers managing accounts on mobile
Not For: Users on shared or family devices who stay logged in
What It Means For You
Connections to the bank's servers are well protected and user data is not shared with advertisers. Some concerns exist around how account information is safeguarded while stored on the device itself. The app uses Firebase for push notifications and Google Maps for branch locations, but collects minimal personal data beyond what banking requires.
Quick Verdict
Best for: OTP Direkt customers managing accounts on mobile
Not For: Users on shared or family devices who stay logged in
What It Means For You
Connections to the bank's servers are well protected and user data is not shared with advertisers. Some concerns exist around how account information is safeguarded while stored on the device itself. The app uses Firebase for push notifications and Google Maps for branch locations, but collects minimal personal data beyond what banking requires.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalCode Security
2 totalPrivacy
2 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
md.mobiasbanca.otpdirekt
Version
3.1.10 (Build 30110)
Analysis Date
Mar 27, 2026
Classes Analyzed
44
Feedback helps us improve our analysis
Data Security - 2 findings (1 high, 1 medium)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 2 findings (2 medium)
The app collects the account and transaction information required for banking services. Data collection is limited to what is necessary for the app to function. Location data may be accessed when users use the branch and ATM locator feature powered by Google Maps.
User personal data is not shared with advertising or marketing companies. Firebase Cloud Messaging is used to deliver push notifications from the bank to the device. Google Maps is used solely to display branch and ATM locations. The authentication framework used for secure login does not share user personal data with third parties for commercial purposes.
| Category | Score |
|---|---|
| Security | 64/100 |
| Privacy | 52/100 |
| Data Security | 48/100 |
| Network Security | 100/100 |
| Code Safety | 85/100 |
| Data Collection | 97/100 |
| Data Sharing | 100/100 |
| User Control | 92/100 |
This scorecard is based on static analysis of the app's code and behavior patterns. Scores reflect the app's practices at the time of analysis and may change with future updates.
Developer not yet contacted