Rabobank Security & Privacy Scorecard
by Rabobank Nederland · iOS
App usage and interactions are measured by Piano Analytics, Google Analytics, and BlueConic, which can build a profile of how users navigate the banking app. Third-party services including Tealium and Split.io also receive data about user sessions. Identity verification involves iProov and Thales ReadID, which process biometric and document data during onboarding.
Best for
Rabobank customers managing daily finances
Findings
- 0 critical
- 0 high
- 3 medium
- 7 low
- 6 info
1 issue identified across security and privacy analysis.
Top security issues
- Fraud detection SDK endpoints (ThreatFabric FRSMobileSDK/CsdIosClient) configured as placeholder URLs in production bundle — silent fraud monitoring failure risk
- Keychain items using non-device-only accessibility class — authentication tokens portable via iCloud backup to attacker-controlled devices
- Development keychain access group (`QK2LQF88J6.nl.Rabobank.Bankieren-dev`) present in production entitlements — dev-signed apps could access production Keychain items
Top privacy issues
- ThreatFabric FRSMobileSDK privacy manifest declares zero data collection despite active device scanning and session-correlated telemetry — GDPR documentation gap
- CsdIosClient (ThreatFabric) ships with no privacy manifest at all while collecting device signals for fraud detection
- DiagnosticsHandler transmits full URLs including query parameters to native layer — potential exposure of session state in OAuth and payment flows
Full analysis
Score: 91/100 (A)
Rabobank's mobile banking app scores highly across all security and privacy categories, with particularly strong network protections and controlled third-party data sharing.
What This Means for You
App usage and interactions are measured by Piano Analytics, Google Analytics, and BlueConic, which can build a profile of how users navigate the banking app. Third-party services including Tealium and Split.io also receive data about user sessions. Identity verification involves iProov and Thales ReadID, which process biometric and document data during onboarding.
Recommendation: Trustworthy
Best For: Rabobank customers managing daily finances
Key Findings
Data Security - 6 findings (1 medium, 4 low, 1 info)
Network Security - 3 findings (3 info)
Code Safety - 0 findings
Privacy - 2 findings (1 medium, 1 info)
Privacy Concerns
What Data is Collected
The app collects behavioral and usage data through Piano Analytics, Google Analytics, and BlueConic, which track how users navigate and interact with banking features. Crash and performance data is gathered through PLCrashReporter. Feedback and in-app survey responses are collected via Usabilla.
Third-Party Data Sharing
Tealium, a data management platform, coordinates data flows between the app and multiple analytics partners. Split.io receives information about user sessions for feature experimentation. iProov and Thales ReadID process biometric and identity document data during account verification and onboarding.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 91/100 |
| Privacy | 91/100 |
| Data Security | 92/100 |
| Network Security | 98/100 |
| Code Safety | 94/100 |
| Data Collection | 91/100 |
| Data Sharing | 98/100 |
| User Control | 93/100 |
Positive Security Features
- Communications between the app and Rabobank's servers are strongly secured, making it very difficult for outside parties to intercept banking data while it travels over the network.
- ThreatFabric fraud detection is integrated into the app, actively monitoring for signs of unauthorized access or device-level threats to protect user accounts.
- The app's code earned a high Code Safety score, reflecting solid protections against unauthorized modification of the app itself.
Areas for Improvement
- The number of analytics and behavioral profiling companies receiving user data is relatively high for a banking app, meaning more organizations can observe how users interact with their finances.
- Consent controls over which tracking services receive user data could be made more visible and actionable within the app, giving users clearer choice over their privacy.
- Minor improvements to how certain data is handled on the device would further reduce the amount of information stored locally beyond what is needed.
About This Analysis
This scorecard is generated from automated static analysis of the app's code and configuration. It reflects what the app is capable of based on its current build, not necessarily every action taken in every session.
App Details
| Field | Value |
|---|---|
| Package | nl.Rabobank.Bankieren |
| Version | 7.55.1 (build 202603241044) |
| Scan Date | 2026-04-09 |
| Analysis Type | Static |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 91/100 |