Rabobank Security & Privacy Scorecard
Android
Device activity is continuously monitored by fraud detection software to guard the user's account against unauthorized access. Usage patterns are shared with a feature analytics service used to test app improvements. When verifying identity in-app, personal data is processed by third-party identity verification providers.
Best for
Everyday Rabobank customers comfortable with fraud
Findings
- 0 critical
- 0 high
- 4 medium
- 5 low
- 9 info
1 issue identified across security and privacy analysis.
Top security issues
- WebView SSL error handling delegates to opaque obfuscated handler (BankierenSslErrorHandler) — if handler.proceed() is called, all WebView TLS validation is bypassed for banking web content
- ReadID SDK ships public disablePinning() method in production — if invoked (including via reflection), MitM attacks become possible on NFC identity verification traffic handling passport biographic data
- DeepLinkActivity accepts rabobank://* wildcard URI scheme from any app with no confirmed input validation — payment schemes including iDEAL and OpenBanking are reachable via crafted intents
Top privacy issues
- ThreatFabric Konversation collects phone call state (IDLE/RINGING/OFFHOOK with timestamps) during banking sessions and transmits to third party without explicit user consent prompt — GDPR transparency concern
- Anti-fraud SDK (ThreatFabric) initialization is feature-flag controlled via Split.io — external service failure can silently disable fraud protection without user awareness
- Split.io feature flag SDK collects installation ID and app version, creating a data subprocessor relationship that should be disclosed in the privacy policy alongside ThreatFabric
Full analysis
Rabobank
Version: 7.53.3 | Scan Date: 2026-02-18
| Score | Rating |
|---|---|
| Overall | 80/100 (B) |
| Security | 78/100 |
| Privacy | 82/100 |
What This Means for You
Device activity is continuously monitored by fraud detection software to guard the user's account against unauthorized access. Usage patterns are shared with a feature analytics service used to test app improvements. When verifying identity in-app, personal data is processed by third-party identity verification providers.
Recommendation: Trustworthy
Best For: Everyday Rabobank customers comfortable with fraud
Key Findings
Data Security - 3 findings (3 low)
Network Security - 3 findings (2 medium, 1 info)
Code Safety - 0 findings
Privacy - 2 findings (1 medium, 1 info)
Privacy Concerns
What Data is Collected
The app collects device identifiers, behavioral patterns, and usage data to support fraud detection and standard banking functionality. When using in-app identity verification, biometric and identity document data is processed. App interaction records and push notification registration details are also collected to support core features.
Third-Party Data Sharing
Device behavior and usage patterns are shared with ThreatFabric (Konversation), a fraud detection service, to protect the user's account from unauthorized access. Feature usage is shared with Split.io, an A/B testing and analytics platform used to evaluate app improvements. Biometric and identity document data is processed by iProov and ReadID (Innovalor) during in-app identity verification steps.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 78/100 |
| Privacy | 82/100 |
| Data Security | 88/100 |
| Network Security | 76/100 |
| Code Safety | 80/100 |
| Data Collection | 85/100 |
| Data Sharing | 90/100 |
| User Control | 88/100 |
Positive Security Features
- Dedicated fraud detection monitoring actively protects the user's account from unauthorized access in real time.
- Biometric identity verification is handled by established third-party specialists, keeping sensitive checks isolated from the core app code.
- Data sharing and user control scores are above average, reflecting stronger-than-typical limits on what information leaves the device.
Areas for Improvement
- Some network communications could use stronger configuration to better protect user data while it travels between the device and banking servers.
- Certain data stored locally on the device could benefit from additional protection layers.
- The app shares usage patterns with a feature analytics service; clearer in-app disclosure would give users better visibility into this practice.
About This Analysis
This scorecard is generated from automated static analysis of the app's compiled code and configuration files. Scores reflect data handling practices, network communication quality, and on-device data protection.
App Details
| Field | Value |
|---|---|
| App Name | Rabobank |
| Package ID | nl.rabomobiel |
| Version | 7.53.3 |
| Scan Date | 2026-02-18 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 80/100 |