Scan results

    AFAS Pocket

    Android

    AFAS Pocket provides Employee Self Service and important ERP functions seamlessly integrated with the Profit back office. Fast insights into actions, tasks, alerts, newsfeed, contact files, hour entry, expense claims, payslips, and leave management.

    CITT SCORE
    86
    out of 100
    TRUSTED

    Quick Verdict

    Best for: AFAS users comfortable with standard analytics

    What It Means For You

    Usage activity is shared with Mixpanel and Firebase for analytics and push notifications. The app can access contacts and calendar when those permissions are granted. Microsoft Intune integration means an organization may manage how the app operates on the device.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (15)

    Data Security

    3 total
    1 Low
    2 Info

    Network Security

    3 total
    3 Info

    Code Security

    5 total
    1 Medium
    2 Low
    2 Info

    Privacy

    2 total
    1 Low
    1 Info

    Third-Party Risk

    1 total
    1 Info

    Permission Usage

    1 total
    1 Info

    Third-Party Services

    Flutter, Microsoft Intune MAM, Firebase Core, Firebase Cloud Messaging (FCM), Firebase Instance ID, Mixpanel Android SDK 8.2.5, Comfortkey / Celsius Benelux BV BLE SDK, Flutter Blue Plus, webview_flutter_android, local_auth (Android BiometricPrompt), flutter_contacts, manage_calendar_events, image_picker, file_picker, share_plus, Apache Tika, Chromium Cronet

    Security Strengths

    • AndroidKeyStore AES-256/CBC with properly randomized IVs for all sensitive credential storage
    • Microsoft Intune MAM enforces conditional access, app PIN, selective wipe, and explicit weak-cipher blocking (RC4, 3DES, MD5)
    • android:allowBackup="false" prevents ADB and cloud backup data extraction
    • Certificate pinning implemented for 2FA endpoint (refinery2fa.afaspocket.nl) with 4 SHA-256 pins
    • No cleartext HTTP traffic — cleartextTrafficPermitted="false" globally enforced
    • Release build correctly hardened — DEBUG=false, no debuggable flag, internal-only install location
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    contacts
    camera
    health

    Package

    nl.afas.pocket2

    Version

    2.33.6 (versionCode: 2330600)

    Analysis Date

    Apr 9, 2026

    Classes Analyzed

    4,926

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Trustworthy

    Key Findings

    Data Security - 3 findings (1 low, 2 info)

    Network Security - 3 findings (3 info)

    Code Safety - 0 findings

    Privacy - 2 findings (1 low, 1 info)

    Privacy Concerns

    What Data is Collected

    The app collects usage and behavioral data through Mixpanel and Firebase. Device identifiers are used to deliver push notifications. When permissions are granted, the app can read contacts and calendar events. Photos and files can also be accessed when those features are used.

    Third-Party Data Sharing

    Behavioral and usage data is shared with Mixpanel for analytics. Firebase receives device and session data to support push notifications and core app services. If an organization has configured Microsoft Intune, enterprise policies may govern how the app operates and what activity data is visible to the IT department.

    Understanding the Scores

    CategoryScore
    Security91/100
    Privacy84/100
    Data Security94/100
    Network Security98/100
    Code Safety92/100
    Data Collection84/100
    Data Sharing92/100
    User Control89/100

    Positive Security Features

    • Biometric authentication support lets users secure access using fingerprint or face recognition instead of a password
    • Enterprise mobile management through Microsoft Intune allows organizations to enforce security policies on the app
    • Network communication received near-perfect scores, indicating strong practices for protecting data in transit

    Areas for Improvement

    • Usage and behavioral data is shared with Mixpanel and Firebase by default, and the app does not provide in-app controls to opt out of this analytics collection.
    • Contact and calendar data becomes accessible once those permissions are granted; users who prefer to limit this can review and adjust permissions in device settings.
    • The app includes Bluetooth access through multiple libraries; if Bluetooth features are not used, this represents a broader permission scope than may be necessary.

    About This Analysis

    This scorecard is based on static analysis of the app's code and configuration. Scores reflect security and privacy practices observed in the version analyzed. Real-world behavior may vary based on server-side configuration and individual usage.

    App Details

    FieldValue
    Packagenl.afas.pocket2
    Version2.33.6 (2330600)
    Scan Date2026-04-09
    PlatformAndroid

    Right of Reply

    Developer not yet contacted