Centraal Beheer Security & Privacy Scorecard
Android
Usage patterns and in-app behavior are tracked by Firebase, Google Analytics, and Microsoft App Center. A third-party firm, Celebrus Technologies, also collects user activity data. Account and policy information is transmitted, and some protections around how that data travels could be stronger.
Best for
Centraal Beheer customers comfortable with standard
Findings
- 3 critical
- 5 high
- 6 medium
- 4 low
- 0 info
1 issue identified across security and privacy analysis.
Top security issues
- Microsoft App Center Secret Hardcoded in Production Code
- Sitecore Content Hub API Key Hardcoded in Retrofit Interface
- Google Tag Manager Dynamic Tag Injection Creates Security Risk
Top privacy issues
- PII Exposure Risk in Analytics Events Without Sanitization
- Eight Analytics SDKs Create Extensive Data Collection Footprint
- No Granular Consent for 8 Analytics Platforms
Full analysis
Centraal Beheer
Version: 7.49.0
Platform: Android
Scan Date: January 25, 2026
What This Means for You
Usage patterns and in-app behavior are tracked by Firebase, Google Analytics, and Microsoft App Center. A third-party firm, Celebrus Technologies, also collects user activity data. Account and policy information is transmitted, and some protections around how that data travels could be stronger.
Recommendation: Use With Caution
Best For: Centraal Beheer customers comfortable with standard
Key Findings
Data Security - 3 findings (1 critical, 2 medium)
Network Security - 5 findings (1 critical, 1 high, 2 medium, 1 low)
Code Safety - 0 findings
Privacy - 5 findings (1 critical, 2 high, 1 medium, 1 low)
Privacy Concerns
What Data is Collected
The app collects behavioral and usage data across multiple channels. Firebase Analytics and Google Analytics record how users navigate and interact with features. Microsoft App Center collects session and diagnostic data. Celebrus Technologies and Usabilla gather additional interaction and behavioral signals. Sitecore Content Hub may process content-related usage information tied to the user session.
Third-Party Data Sharing
User activity data flows to at least nine external services. Google Tag Manager coordinates data routing across Google's advertising and analytics ecosystem. Celebrus Technologies receives behavioral profiles that extend beyond the app's core insurance functions. Usabilla shares feedback and interaction data with its parent organization. Firebase Crashlytics and Firebase Performance Monitoring transmit diagnostic information to Google's infrastructure.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 65/100 |
| Privacy | 55/100 |
| Data Security | 70/100 |
| Network Security | 65/100 |
| Code Safety | 75/100 |
| Data Collection | 50/100 |
| Data Sharing | 45/100 |
| User Control | 60/100 |
Positive Security Features
- The app uses well-maintained, industry-standard networking libraries (OkHttp, Retrofit) that receive regular security updates from their maintainers.
- Apollo GraphQL provides a structured approach to data requests, which limits the surface area for unintended data exposure during server communication.
Areas for Improvement
- The protections governing how account and policy data travels between the app and servers have gaps that could be closed with stronger safeguards.
- Behavioral data is routed to a large number of third-party organizations, several of which operate beyond the user's direct awareness or control.
- The app provides limited built-in options for users to review or restrict what information is collected during normal use.
About This Analysis
This scorecard is based on automated static analysis of the app's compiled code and configuration. Scores reflect the app's state at the time of the scan and may change as the app is updated.
App Details
- App Name: Centraal Beheer
- Package ID: nl.centraalbeheer.centraalbeheerapp
- Version: 7.49.0
- Scan Date: January 25, 2026
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 60/100 |