ING Netherlands Security & Privacy Scorecard

by ING · iOS

89
Overall trust score
Trustworthy
90
Security
88
Privacy

Account activity and device information are processed through IBM Trusteer fraud detection and Sentry error reporting. Identity verification uses Mitek and iProov, meaning biometric and document data is handled by third-party services during onboarding. In-app actions and crash data are shared with these partners as part of normal operation.

Best for

ING customers managing everyday banking on the go

Findings

  • 0 critical
  • 0 high
  • 3 medium
  • 5 low
  • 5 info

1 issue identified across security and privacy analysis.

Top security issues

  • MSF Plugin XHR/Fetch Intercept Matches on Hostname Prefix Only — No Domain Scope Enforcement
  • FileTransfer Plugin Accepts Caller-Supplied Upload URL Without Allowlist Validation
  • executeNativeFunction Bridge Exposes Arbitrary Native Dispatch Without Allowlist

Top privacy issues

  • tazSDK Privacy Manifest Does Not Declare Behavioral Biometrics Data Collection
  • MobileFlow Privacy Manifest Contains Malformed Placeholder Entry
  • Keychain Accessibility Level Not Verifiable for Financial Credential Storage

Full analysis

What This Means for You

Account activity and device information are processed through IBM Trusteer fraud detection and Sentry error reporting. Identity verification uses Mitek and iProov, meaning biometric and document data is handled by third-party services during onboarding. In-app actions and crash data are shared with these partners as part of normal operation.

Recommendation: Trustworthy

Best For: ING customers managing everyday banking on the go

Key Findings

Data Security - 3 findings (1 medium, 2 info)

Network Security - 5 findings (2 medium, 1 low, 2 info)

Code Safety - 0 findings

Privacy - 0 findings

Privacy Concerns

What Data is Collected

Account activity, device identifiers, and usage patterns are collected as part of normal app operation. During onboarding and identity verification, biometric data and identity document details are processed by third-party services. Error and crash information is collected automatically when the app encounters problems.

Third-Party Data Sharing

User data is shared with the following third-party services:

  • IBM Trusteer (tazSDK): Receives account activity and device information for fraud detection purposes
  • Mitek Systems (MiSnap): Receives identity document data during onboarding
  • iProov: Receives biometric data for identity verification
  • Sentry: Receives crash reports and error data for quality monitoring
  • Twilio: Handles in-app voice and messaging communications

Understanding the Scores

Category Score
Security 90/100
Privacy 88/100
Data Security 94/100
Network Security 89/100
Code Safety 96/100
Data Collection 88/100
Data Sharing 92/100
User Control 93/100

Positive Security Features

  • Strong data security practices limit exposure of sensitive account information stored on the device
  • High code safety rating reflects disciplined software development standards throughout the app
  • Data sharing is restricted to services with clearly defined functional purposes

Areas for Improvement

  • Some network communications have configurations that could be further hardened to better protect user data in transit
  • A small number of data storage practices could be strengthened to meet the highest standards expected of a banking application
  • The scope of device and behavioral data collected by fraud-detection services could be more clearly disclosed to users

About This Analysis

This scorecard is generated from automated static analysis of the app binary. Scores reflect the security and privacy posture observed at the time of the scan and do not include runtime testing.

App Details

Field Value
Package ID nl.ing.iphone.app.Bankieren
Version 2026.6.1 (Build 20260325.112311)
Scan Date 2026-04-09
Platform iOS

Versions & scan history

ScanDateOverall score
#1 (current) 89/100