ING Netherlands Security & Privacy Scorecard
by ING · iOS
Account activity and device information are processed through IBM Trusteer fraud detection and Sentry error reporting. Identity verification uses Mitek and iProov, meaning biometric and document data is handled by third-party services during onboarding. In-app actions and crash data are shared with these partners as part of normal operation.
Best for
ING customers managing everyday banking on the go
Findings
- 0 critical
- 0 high
- 3 medium
- 5 low
- 5 info
1 issue identified across security and privacy analysis.
Top security issues
- MSF Plugin XHR/Fetch Intercept Matches on Hostname Prefix Only — No Domain Scope Enforcement
- FileTransfer Plugin Accepts Caller-Supplied Upload URL Without Allowlist Validation
- executeNativeFunction Bridge Exposes Arbitrary Native Dispatch Without Allowlist
Top privacy issues
- tazSDK Privacy Manifest Does Not Declare Behavioral Biometrics Data Collection
- MobileFlow Privacy Manifest Contains Malformed Placeholder Entry
- Keychain Accessibility Level Not Verifiable for Financial Credential Storage
Full analysis
What This Means for You
Account activity and device information are processed through IBM Trusteer fraud detection and Sentry error reporting. Identity verification uses Mitek and iProov, meaning biometric and document data is handled by third-party services during onboarding. In-app actions and crash data are shared with these partners as part of normal operation.
Recommendation: Trustworthy
Best For: ING customers managing everyday banking on the go
Key Findings
Data Security - 3 findings (1 medium, 2 info)
Network Security - 5 findings (2 medium, 1 low, 2 info)
Code Safety - 0 findings
Privacy - 0 findings
Privacy Concerns
What Data is Collected
Account activity, device identifiers, and usage patterns are collected as part of normal app operation. During onboarding and identity verification, biometric data and identity document details are processed by third-party services. Error and crash information is collected automatically when the app encounters problems.
Third-Party Data Sharing
User data is shared with the following third-party services:
- IBM Trusteer (tazSDK): Receives account activity and device information for fraud detection purposes
- Mitek Systems (MiSnap): Receives identity document data during onboarding
- iProov: Receives biometric data for identity verification
- Sentry: Receives crash reports and error data for quality monitoring
- Twilio: Handles in-app voice and messaging communications
Understanding the Scores
| Category | Score |
|---|---|
| Security | 90/100 |
| Privacy | 88/100 |
| Data Security | 94/100 |
| Network Security | 89/100 |
| Code Safety | 96/100 |
| Data Collection | 88/100 |
| Data Sharing | 92/100 |
| User Control | 93/100 |
Positive Security Features
- Strong data security practices limit exposure of sensitive account information stored on the device
- High code safety rating reflects disciplined software development standards throughout the app
- Data sharing is restricted to services with clearly defined functional purposes
Areas for Improvement
- Some network communications have configurations that could be further hardened to better protect user data in transit
- A small number of data storage practices could be strengthened to meet the highest standards expected of a banking application
- The scope of device and behavioral data collected by fraud-detection services could be more clearly disclosed to users
About This Analysis
This scorecard is generated from automated static analysis of the app binary. Scores reflect the security and privacy posture observed at the time of the scan and do not include runtime testing.
App Details
| Field | Value |
|---|---|
| Package ID | nl.ing.iphone.app.Bankieren |
| Version | 2026.6.1 (Build 20260325.112311) |
| Scan Date | 2026-04-09 |
| Platform | iOS |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 89/100 |