Scan results

    Rabobank

    Android

    Smart and secure banking with the Rabo App. Check balances, transfer money, send payment requests, manage budgets, set savings goals, and access all your Rabobank products including insurance. Secure login with face recognition, fingerprint, or access code.

    CITT SCORE
    80
    out of 100
    TRUSTED

    Quick Verdict

    Best for: Everyday Rabobank customers comfortable with fraud

    What It Means For You

    Device activity is continuously monitored by fraud detection software to guard the user's account against unauthorized access. Usage patterns are shared with a feature analytics service used to test app improvements. When verifying identity in-app, personal data is processed by third-party identity verification providers.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (14)

    Data Security

    3 total
    3 Low

    Network Security

    3 total
    2 Medium
    1 Info

    Code Security

    5 total
    1 Medium
    2 Low
    2 Info

    Privacy

    2 total
    1 Medium
    1 Info

    Third-Party Risk

    1 total
    1 Info

    Third-Party Services

    Firebase Messaging, Google ML Kit, Google Play Services, Google Tink, iProov, ReadID (Innovalor), BouncyCastle, SCUBA, Split.io, Glide, OkHttp3, AndroidX Room, ThreatFabric (Konversation), Koin

    Security Strengths

    • Certificate pinning implemented — 7 SHA-256 SPKI pins for rabobank.nl with all subdomain coverage
    • Cleartext traffic blocked globally (cleartextTrafficPermitted="false") — only system CA trust anchors accepted
    • Authentication tokens encrypted using EncryptedSharedPreferences with AES-256-SIV/AES-256-GCM backed by Android KeyStore
    • Device identity and biometric keys use hardware-backed Android KeyStore RSA-2048 with StrongBox attempt — private keys never leave secure hardware
    • android:allowBackup="false" prevents ADB and cloud backup extraction of app data
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    biometric
    nfc
    payments

    Package

    nl.rabomobiel

    Version

    7.53.3

    Analysis Date

    Feb 18, 2026

    Classes Analyzed

    31,088

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Trustworthy

    Key Findings

    Data Security - 3 findings (3 low)

    Network Security - 3 findings (2 medium, 1 info)

    Code Safety - 0 findings

    Privacy - 2 findings (1 medium, 1 info)

    Privacy Concerns

    What Data is Collected

    The app collects device identifiers, behavioral patterns, and usage data to support fraud detection and standard banking functionality. When using in-app identity verification, biometric and identity document data is processed. App interaction records and push notification registration details are also collected to support core features.

    Third-Party Data Sharing

    Device behavior and usage patterns are shared with ThreatFabric (Konversation), a fraud detection service, to protect the user's account from unauthorized access. Feature usage is shared with Split.io, an A/B testing and analytics platform used to evaluate app improvements. Biometric and identity document data is processed by iProov and ReadID (Innovalor) during in-app identity verification steps.

    Understanding the Scores

    CategoryScore
    Security78/100
    Privacy82/100
    Data Security88/100
    Network Security76/100
    Code Safety80/100
    Data Collection85/100
    Data Sharing90/100
    User Control88/100

    Positive Security Features

    • Dedicated fraud detection monitoring actively protects the user's account from unauthorized access in real time.
    • Biometric identity verification is handled by established third-party specialists, keeping sensitive checks isolated from the core app code.
    • Data sharing and user control scores are above average, reflecting stronger-than-typical limits on what information leaves the device.

    Areas for Improvement

    • Some network communications could use stronger configuration to better protect user data while it travels between the device and banking servers.
    • Certain data stored locally on the device could benefit from additional protection layers.
    • The app shares usage patterns with a feature analytics service; clearer in-app disclosure would give users better visibility into this practice.

    About This Analysis

    This scorecard is generated from automated static analysis of the app's compiled code and configuration files. Scores reflect data handling practices, network communication quality, and on-device data protection.

    App Details

    FieldValue
    App NameRabobank
    Package IDnl.rabomobiel
    Version7.53.3
    Scan Date2026-02-18

    Right of Reply

    Developer not yet contacted