Scan results

    Expensify - Travel & Expense

    Android

    Expensify helps millions track expenses, reimburse employees, manage corporate cards, send invoices, pay bills, and book travel, all integrated with chat. Supports self-employed, small business, growing teams, and enterprises with accounting software integrations.

    unTRUSTED

    This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.

    The five trust checks

    Truly LocalNot applicable
    CITT SCORE
    65
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Business travelers managing expense reports

    Not For: Users preferring financial activity not logged by analytics

    What It Means For You

    In-app interaction and session data is shared with FullStory, Firebase Analytics, and Urban Airship. Financial account connections are managed through Plaid, and identity verification through Onfido. The app also bundles Group-IB fraud detection and Sentry error reporting.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (9)

    Data Security

    1 total
    1 Medium

    Network Security

    2 total
    1 Medium
    1 Low

    Code Security

    4 total
    1 High
    2 Medium
    1 Low

    Privacy

    1 total
    1 High

    Third-Party Risk

    1 total
    1 Medium

    Third-Party Services

    FullStory, Group-IB Fraud Hunting Platform (FHP) SDK, Firebase Analytics, Firebase Auth, Firebase Messaging (FCM), Urban Airship, Plaid Link, Onfido, Mapbox, Pusher, Sentry React Native, Google Sign-In, Google MLKit, Google Play Install Referrer, Realm, React Native (Hermes), Expo, Vision Camera, Lottie, WorkManager

    Security Strengths

    • New credential writes use hardware-backed Android Keystore AES-GCM-256 encryption
    • Login sessions and auth tokens are wiped completely from the device on sign-out
    • User passwords are never stored on disk at any point — only a device-specific credential token is saved
    • Firebase Crashlytics disabled — crash data is not sent to Google
    • Structured API call logs redact 20+ sensitive fields including auth tokens and card numbers
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    location
    camera
    ads

    Package

    org.me.mobiexpensifyg

    Version

    9.4.0-7 (versionCode 509040007)

    Analysis Date

    Aug 11, 2026

    Classes Analyzed

    29,997

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security: 1 finding (1 medium)

    Network Security: 2 findings (1 medium, 1 low)

    Code Security: 4 findings (1 high, 2 medium, 1 low)

    Privacy: 1 finding (1 high)

    Third-Party Risk: 1 finding (1 medium)

    Privacy Concerns

    What Leaves the Device

    The build links FullStory, an in-session recording service. Session interactions and screen content may be shared with FullStory's platform; runtime behavior was not tested. Firebase Analytics is linked and behavioral event data may be shared with Google's analytics infrastructure; runtime flows were not observed. Urban Airship is linked for push notification delivery and device identifiers may be shared with Airship's platform; runtime data flows were not tested. Plaid Link is bundled for financial account connection flows and account access data may be shared with Plaid's infrastructure; runtime flows were not observed. Onfido is bundled for identity verification and personal identity documents may be shared with Onfido's servers; runtime behavior was not tested. Group-IB Fraud Hunting Platform SDK is linked and device signals may be shared with Group-IB's fraud analysis infrastructure; runtime transmission was not observed. Sentry React Native is linked and error report data may be shared with Sentry; runtime behavior was not tested.

    What Stays on the Device

    The build includes Realm for local database storage, keeping structured data under local device control. Google MLKit is linked for on-device machine learning processing. Lottie handles animation rendering locally. React Native with the Hermes engine handles application logic on the device. Data processed through these components does not leave the device through those libraries.

    Third-Party Data Sharing

    The build integrates analytics and session recording libraries from FullStory and Firebase Analytics. Push notification delivery is provided through Urban Airship. Financial account connection functionality is provided through Plaid Link. Identity verification functionality is provided through Onfido. Fraud detection functionality is provided through the Group-IB Fraud Hunting Platform SDK. Error reporting is provided through Sentry. Navigation and mapping is provided by Mapbox. Real-time event delivery is provided by Pusher. Authentication is provided by Firebase Auth and Google Sign-In.

    Understanding the Scores

    Security: 72/100 (Solid)
    CITT rates this build's overall security posture as solid. Network security contributes positively to this score, while the data security sub-score placed the overall figure in this range.

    Privacy: 62/100 (Use With Caution)
    CITT rates this build's privacy posture as use with caution. The build links multiple analytics, session recording, and third-party data service libraries, which contributes to this rating.

    Data Security: 58/100 (Use With Caution)
    CITT rates this build's data security as use with caution. A medium-severity finding in this category contributed to this score.

    Network Security: 80/100 (Trustworthy)
    CITT rates this build's network security posture as trustworthy. Network-layer protections present in this build contributed to this strong rating.

    Code Safety: 72/100 (Solid)
    CITT rates this build's code safety posture as solid. One high-severity finding alongside medium and low findings in the code security category placed this score in the solid range.

    Data Collection: 60/100 (Use With Caution)
    CITT rates this build's data collection scope as use with caution. The build links multiple analytics services and a session recording library, contributing to this score.

    Data Sharing: 62/100 (Use With Caution)
    CITT rates this build's data sharing practices as use with caution. The build links services from multiple third-party providers across analytics, identity verification, fraud detection, and financial account management categories.

    User Control: 65/100 (Use With Caution)
    CITT rates this build's user control provisions as use with caution. The extent to which users can adjust or limit data flows from the various integrated services could not be confirmed from static analysis alone; runtime testing was not performed.

    Positive Security Features

    No positive security practices were identified in the analyzed build.

    Areas for Improvement

    • The data security sub-score of 58 reflects a medium-severity finding in how stored data is handled in this build. Improving data storage practices would raise this score into the solid range.
    • The breadth of analytics, session recording, and behavioral profiling services integrated in this build means financial activity and in-app behavior may be logged by multiple third parties. The extent of user opt-out controls could not be confirmed from static analysis; runtime testing was not performed.
    • The code security category contains one high-severity finding alongside additional medium and low findings, indicating room to strengthen safe coding practices in this build.

    About This Analysis

    App Details

    FieldValue
    AppExpensify - Travel & Expense
    Package IDorg.me.mobiexpensifyg
    Version9.4.0-7 (versionCode 509040007)
    Scan Date2026-08-11
    Analysis MethodStatic analysis

    Right of Reply

    Developer not yet contacted

    Analyzed 2026-08-11 · ruleset citt-ruleset-2026-08-v1 · artifact binary not retained

    Right of Reply

    Developer not yet contacted

    Corrections

    This report has been updated since it was first published. Every change to a public claim is recorded here.

    • 2026-08-11·Quick verdict updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·What this means for you updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·Public scorecard updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·Quick verdict updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·What this means for you updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·Public scorecard updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·Quick verdict updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·What this means for you updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·Public scorecard updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·Quick verdict updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·What this means for you updatedAutomated regeneration changed a published public claim.
    • 2026-08-11·Public scorecard updatedAutomated regeneration changed a published public claim.