Private, end-to-end encrypted two-factor authentication app by Proton. Open-source, offline-capable, and backed by Swiss privacy laws. Syncs 2FA codes securely across devices without requiring a Proton account.
This app did not meet one of the trust checks in this assessment.
The five trust checks
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
1 totalCode Security
1 totalThird-Party Risk
1 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
proton.android.authenticator
Version
1.3.7 (versionCode 10307329)
Analysis Date
Jun 26, 2026
Classes Analyzed
19,607
Feedback helps us improve our analysis
Excellent for secure two-factor authentication. Open-source, strongly encrypted with verified server connections, and sends zero tracking data. Works offline without a Proton account.
Data Security - 1 finding (1 low)
Network Security - 0 findings
Code Safety - 1 finding (1 high)
Privacy - 1 finding (1 info)
No third-party data sharing was identified in this analysis.
Security: 88/100
Privacy: 100/100
The app's privacy practices could be strengthened by:
Single sign-on input validation
When logging in with single sign-on, the app currently accepts login inputs from other apps on your device without verifying their origin. Adding stricter origin verification would reduce the risk of a malicious co-installed app interfering with the login process.
Screen protection for displayed verification codes
On devices running Android 12 or earlier, or when biometric lock is turned off, displayed 2FA codes could potentially be captured by apps with screen recording access. Enabling full screen protection by default would close this gap.
App Type: Two-factor authentication, sensitive account security
Classes Analyzed: 19,607
Third-Party Services: 13
Context Tags: sensitive_data, authentication, 2fa, privacy
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
Developer: Proton AG
Version: 1.3.7 (Build 10307329)
Analysis Date: June 26, 2026
Package: proton.android.authenticator
Developer not yet contacted