Scan results

    ONPEID

    Android

    ONPEID is a mobile application developed by the National Electoral Processes Office (ONPE) that allows Peruvian citizens to identify themselves using their electronic DNI (version 2) to access digital voting boxes for remote electoral processes. Requires NFC protocol and digital certificate PIN.

    CITT SCORE
    81
    out of 100
    TRUSTED

    Quick Verdict

    Best for: Peruvian citizens verifying official IDs

    What It Means For You

    App usage data is reported to Firebase, a Google service, for app configuration and diagnostics. The app collects minimal personal data and does not share it with advertising or marketing companies. ID verification activity stays largely on-device.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (5)

    Data Security

    1 total
    1 High

    Network Security

    2 total
    1 High
    1 Medium

    Code Security

    1 total
    1 Medium

    Privacy

    1 total
    1 Medium

    Third-Party Services

    Firebase Remote Config, Firebase Installations, Firebase Core, Huawei AGConnect, Bouncy Castle, JMRTD, SCUBA, OkHttp3, Ktor Client

    Security Strengths

    • Certificate pinning implemented for all ONPE backend domains
    • WebView-free architecture eliminates entire class of web-based vulnerabilities
    • Modern cryptography with Bouncy Castle (AES-256-GCM, ECDSA P-256)
    • Backup disabled (allowBackup=false) prevents ADB backup extraction
    • No invasive analytics SDKs - only infrastructure telemetry
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    government
    electoral
    authentication
    sensitive data
    nfc
    identity verification
    financial

    Package

    pe.gob.onpe.id.validator

    Version

    1.2.0.82

    Analysis Date

    Feb 5, 2026

    Classes Analyzed

    8,592

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Acceptable

    Key Findings

    Data Security - 1 finding (1 high)

    Network Security - 2 findings (1 high, 1 medium)

    Code Safety - 0 findings

    Privacy - 1 finding (1 medium)

    Privacy Concerns

    What Data is Collected

    ONPEID collects minimal personal data. The app focuses on on-device ID document verification and does not transmit personal identification information to advertising or data broker services. Diagnostic and configuration data is sent to Firebase to keep the app running reliably.

    Third-Party Data Sharing

    App usage and configuration data is shared with Firebase (a Google service) for diagnostics and remote configuration. Huawei AGConnect services are present for Huawei device compatibility. No data is shared with advertising or marketing companies.

    Understanding the Scores

    CategoryScore
    Security72/100
    Privacy90/100
    Data Security75/100
    Network Security70/100
    Code Safety88/100
    Data Collection100/100
    Data Sharing90/100
    User Control100/100

    Positive Security Features

    • Uses established, open-source libraries for document reading and cryptographic operations
    • Collects minimal personal data, earning a perfect Data Collection score
    • Provides full user control with no unnecessary data permissions
    • Implements open standards for machine-readable travel document verification

    Areas for Improvement

    • Data stored on the device could be better protected to reduce the risk of unauthorized access if the device is lost or compromised
    • Some network connections lack the strongest available protections for data sent between the device and remote services
    • One privacy-related practice could be made more transparent to give users a clearer picture of how their information is handled

    About This Analysis

    This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect the security and privacy practices observed at the time of the scan.

    App Details

    FieldValue
    App NameONPEID
    Package IDpe.gob.onpe.id.validator
    Version1.2.0.82
    Scan Date2026-02-05

    Right of Reply

    Developer not yet contacted