Scan results

    ING Netherlands

    iOS

    ING Bankieren — Official mobile banking app offering secure account management, transfers, and iDEAL payment integration for ING customers in the Netherlands.

    CITT SCORE
    89
    out of 100
    TRUSTED

    Quick Verdict

    Best for: ING customers managing everyday banking on the go

    What It Means For You

    Account activity and device information are processed through IBM Trusteer fraud detection and Sentry error reporting. Identity verification uses Mitek and iProov, meaning biometric and document data is handled by third-party services during onboarding. In-app actions and crash data are shared with these partners as part of normal operation.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (13)

    Data Security

    3 total
    1 Medium
    2 Info

    Network Security

    5 total
    2 Medium
    1 Low
    2 Info

    Code Security

    3 total
    2 Low
    1 Info

    Third-Party Risk

    2 total
    2 Low

    Third-Party Services

    tazSDK (IBM Trusteer Pinpoint Detect), MiSnap (Mitek Systems), ReadID_UI, iProov, MobileFlow, Sentry, TwilioVoice, TwilioConversations, Kingfisher, Lottie, libPhoneNumberiOS

    Security Strengths

    • Hardware-backed device binding authentication (PSD2 SCA compliant via TPASecuritySDK)
    • Consistent Keychain usage for all sensitive data — no plaintext credential storage found
    • WebView origin enforcement via allowedDomains mitigates JS bridge attack surface
    • Type-safe URL parsing with cryptographic signature validation for iDEAL payment deep links
    • EU-only Sentry crash reporting endpoint (GDPR-aligned data residency)
    • UserDefaults restricted to non-sensitive SDK configuration only
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    biometric
    identity verification
    payments

    Package

    nl.ing.iphone.app.Bankieren

    Version

    2026.6.1 (Build 20260325.112311)

    Analysis Date

    Apr 9, 2026

    Classes Analyzed

    4,383

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on App Store

    Recommendation: Trustworthy

    Key Findings

    Data Security - 3 findings (1 medium, 2 info)

    Network Security - 5 findings (2 medium, 1 low, 2 info)

    Code Safety - 0 findings

    Privacy - 0 findings

    Privacy Concerns

    What Data is Collected

    Account activity, device identifiers, and usage patterns are collected as part of normal app operation. During onboarding and identity verification, biometric data and identity document details are processed by third-party services. Error and crash information is collected automatically when the app encounters problems.

    Third-Party Data Sharing

    User data is shared with the following third-party services:

    • IBM Trusteer (tazSDK): Receives account activity and device information for fraud detection purposes
    • Mitek Systems (MiSnap): Receives identity document data during onboarding
    • iProov: Receives biometric data for identity verification
    • Sentry: Receives crash reports and error data for quality monitoring
    • Twilio: Handles in-app voice and messaging communications

    Understanding the Scores

    CategoryScore
    Security90/100
    Privacy88/100
    Data Security94/100
    Network Security89/100
    Code Safety96/100
    Data Collection88/100
    Data Sharing92/100
    User Control93/100

    Positive Security Features

    • Strong data security practices limit exposure of sensitive account information stored on the device
    • High code safety rating reflects disciplined software development standards throughout the app
    • Data sharing is restricted to services with clearly defined functional purposes

    Areas for Improvement

    • Some network communications have configurations that could be further hardened to better protect user data in transit
    • A small number of data storage practices could be strengthened to meet the highest standards expected of a banking application
    • The scope of device and behavioral data collected by fraud-detection services could be more clearly disclosed to users

    About This Analysis

    This scorecard is generated from automated static analysis of the app binary. Scores reflect the security and privacy posture observed at the time of the scan and do not include runtime testing.

    App Details

    FieldValue
    Package IDnl.ing.iphone.app.Bankieren
    Version2026.6.1 (Build 20260325.112311)
    Scan Date2026-04-09
    PlatformiOS

    Right of Reply

    Developer not yet contacted