Messaging app offering end-to-end encrypted messages, calls, and video chats with contact discovery and photo/video sharing features.
This app did not meet one of the trust checks in this assessment.
The five trust checks
Quick Verdict
Best for: Everyday messaging with content kept away from third parties
What It Means For You
Messages and calls are protected by end-to-end encryption, meaning Meta cannot read message content. No third-party analytics or advertising services receive data; all telemetry stays within Meta's own infrastructure. Contacts are shared only with Meta-owned systems, and no advertising identifier is collected.
Quick Verdict
Best for: Everyday messaging with content kept away from third parties
What It Means For You
Messages and calls are protected by end-to-end encryption, meaning Meta cannot read message content. No third-party analytics or advertising services receive data; all telemetry stays within Meta's own infrastructure. Contacts are shared only with Meta-owned systems, and no advertising identifier is collected.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Code Security
3 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
net.whatsapp.WhatsApp
Version
26.31.74 (Build 1035496826 / FBAppVersion 2.26.31.74)
Analysis Date
Aug 13, 2026
Classes Analyzed
3,400
Feedback helps us improve our analysis
CITT rates WhatsApp trustworthy: message content is protected by Signal Protocol end-to-end encryption so Meta cannot read it, iCloud backups use hardware-bound encryption that is inaccessible to Apple, and no third-party analytics or advertising SDKs are present in this build. MetaAI conversations are processed on Meta's servers without end-to-end encryption and may be retained on those servers.
Data Security: 0 findings
Network Security: 0 findings
Code Safety: 3 findings (3 low)
Privacy: 0 findings
Third parties that may receive data from the app:
Security: 91/100
Privacy: 80/100
Observations about disclosure, each stated against the published guidance so a reader can compare:
Privacy Manifest Advertising Purpose Declaration
Apple's App Store privacy guidelines encourage developers to declare their data-use purposes in a privacy manifest (Apple developer documentation). The privacy manifest in this build declares third-party advertising purposes in its required-reason API entries while the NSPrivacyTracking flag is set to false. Readers comparing these two values may find them inconsistent; whether this precisely reflects the current data practices could not be determined from the binary alone.
Contact Upload Disclosure
The permission string in this build explicitly discloses that contact information may be uploaded to WhatsApp's servers for contact discovery. This disclosure is in line with Apple's requirement for clear permission descriptions. Users who prefer not to share their contact list can decline the contacts permission; core messaging functionality continues with manual number entry.
App Transport Security Scope
The build applies a global App Transport Security override across all bundle targets. Narrowing this to the specific domains that require it would reduce the potential surface for network-level risks.
Default File Protection Level
App files in this build default to Class B protection, meaning they are accessible when the device is locked. Raising the default to Class C would ensure app files are inaccessible in a locked-device state.
Debug Interfaces in Production
The production binary includes debug Bonjour service registrations and an internal automation interface. Removing these before submission would reduce the information available to someone who analyzes the binary.
App Type: Encrypted messaging, high sensitivity (contacts, messages, media, payments)
Classes Analyzed: 3,400
Third-Party Services: 1 (Ipification)
Context Tags: social, contacts, camera, sensitive_data, financial
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of iOS applications, intended to help people make informed decisions about app security and privacy.
Developer: WhatsApp LLC (Meta Platforms)
Version: 26.31.74 (Build 1035496826)
Analysis Date: 2026-08-13
Package: net.whatsapp.WhatsApp
Developer not yet contacted