Scan results

    George Romania

    Android

    Smart mobile banking from Romania's BCR. Send transfers, pay bills, scan IBANs with your camera, track accounts, and manage finances with fingerprint or pattern lock. Available on phones and tablets.

    NOT ASSESSED

    This app has an open trust check or a verdict held for review.

    The five trust checks

    CITT SCORE
    93
    out of 100
    NOT ASSESSED

    Quick Verdict

    Best for: Everyday banking with strong privacy defaults

    What It Means For You

    Analytics data flows through BCR's own infrastructure rather than directly to third-party companies, limiting external data exposure. Sentry, PostHog, and LUX telemetry are all proxied server-side. Firebase analytics collection is disabled by default.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (9)

    Data Security

    3 total
    2 Low
    1 Info

    Network Security

    1 total
    1 Low

    Code Security

    4 total
    2 Medium
    2 Low

    Third-Party Risk

    1 total
    1 Medium

    Third-Party Services

    Dynatrace OneAgent, Sentry, Crowdin, ThreatMark, RootBeer, Innovatrics DOT, HID Global, Erste Locker, NimbusDS JOSE, Pago SDK, Google Pay, Microblink PhotoPay, Google ML Kit, SQLCipher, Bouncy Castle, Azure Communication Services, GetStream, Firebase Cloud Messaging, Google Maps, PostHog, LUX (Erste Group), JMRTD

    Security Strengths

    • Cleartext traffic globally blocked via network security config with no HTTP exemptions
    • Certificate pinning at both OS (NSC) and application (OkHttp interceptor) layers for all banking domains
    • allowBackup=false prevents Android backup exposure of sensitive data
    • SQLCipher encrypted databases for Pago payment data with derived keys
    • AndroidKeyStore-backed AES/GCM encryption for auth and KYC data with user authentication required
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    camera
    location

    Package

    ro.bcr.georgego

    Version

    26.14.19-google (versionCode 2614192)

    Analysis Date

    Jun 13, 2026

    Classes Analyzed

    53,836

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Very Secure

    Excellent security foundation with encrypted payment databases, biometric authentication, and multi-layered fraud detection. Analytics and crash reporting are routed through BCR's own infrastructure rather than sent directly to outside parties. Recommended for BCR customers seeking reliable mobile banking on Android.

    Key Findings

    Data Security - 3 findings (2 low, 1 info)

    Network Security - 1 finding (1 low)

    Code Safety - 4 findings (2 medium, 2 low)

    Privacy - 1 finding (1 medium)

    Privacy Concerns

    What Data is Collected

    • Personal banking details (account numbers, transaction history): sent to BCR servers for core banking operations
    • Device performance metrics and app diagnostics: sent to monitoring services via BCR's own proxy infrastructure
    • Device identifiers: may be used for fraud detection purposes
    • Location: accessed on your device when using location-aware features; may be shared for fraud detection
    • Contacts: accessed on your device to help autofill transfer recipients

    Third-Party Data Sharing

    The following third parties may receive your data:

    • Dynatrace - Application performance monitoring and diagnostics
    • Google (Firebase Cloud Messaging) - Push notification delivery
    • Google Pay - Payment processing when using Google Pay
    • Google Maps - Map and location display features
    • ThreatMark - Behavioral fraud detection

    Understanding the Scores

    Security: 92/100
    Privacy: 95/100

    Security Breakdown

    • Data Security: 95/100 - Payment and authentication data is encrypted with hardware-backed keys. Sensitive databases use strong encryption and banking data backup is disabled to prevent it from being copied via device backups.
    • Network Security: 97/100 - All banking connections are encrypted with no exceptions for any domain. Banking servers are protected with multiple layers of connection security, and app links use verified domain ownership.
    • Code Safety: 86/100 - Strong core security practices throughout, with some internal component access controls that could be further hardened to reduce the risk of manipulation by other apps on the device.

    Privacy Breakdown

    • Data Collection: 100/100 - Data collection is minimal and purposeful, focused on what is necessary for banking and fraud prevention. Analytics auto-initialization is disabled by default.
    • Data Sharing: 97/100 - Direct third-party data flows are tightly limited. Analytics, crash reporting, and behavioral monitoring are proxied through BCR's own backend rather than sent directly to outside parties.
    • User Control: 100/100 - Biometric authentication with fingerprint or PIN gives you full control over app access, and hardware-backed keys require your direct authentication before unlocking sensitive operations.

    Positive Security Features

    • All network connections require encryption with no exceptions for any domain
    • Payment databases use strong encryption with keys derived from secure storage
    • Authentication and identity data is secured with hardware-backed encryption requiring your biometric or PIN
    • Biometric authentication requires hardware-level user verification before unlocking sensitive operations
    • Multiple layers of fraud detection including behavioral analysis and device integrity checks running in an isolated process
    • Analytics, crash reporting, and monitoring data are routed through BCR's own servers rather than sent directly to third-party vendors
    • Android backup of app data is disabled, preventing sensitive banking data from being copied via device backups
    • Google Pay integration validates the calling app's identity before processing payment intents
    • App links use verified domain ownership to prevent link-hijacking by other installed apps
    • Push notification analytics auto-initialization is disabled in the app manifest

    Areas for Improvement

    GDPR / CCPA Compliance

    The app's privacy practices could be strengthened by:

    1. Banking Response Capture Scope
      The crash reporting integration may capture portions of banking server responses when errors occur, including data such as account balances or transaction details. Restricting capture to non-sensitive error metadata would further protect financial data in error scenarios.

    2. Screen Content Protection
      Enabling screen content protection for sensitive screens would prevent account balances and transaction details from appearing in the device's recent apps switcher or being captured by screen recording tools.

    Security Enhancements

    1. Internal Component Access Controls
      Some in-app browser and transaction signing components accept requests from any source on the device without verifying the requesting app's identity. Adding caller verification to these components would reduce the risk of other installed apps manipulating these flows.

    2. Safe Browsing for In-App Store
      The in-app marketplace browser has Google's Safe Browsing protection disabled. Re-enabling this feature would add a layer of protection against malicious or deceptive content if the store backend were ever compromised.

    3. Development Tools in Production Build
      A translation preview component intended for internal development and QA testing remains included in the production app. While currently low-risk, removing development-only tools from production builds is considered good practice for reducing unnecessary attack surface.

    Technical Context

    App Type: Mobile banking - financial services, high sensitivity
    Classes Analyzed: 53,836
    Third-Party Services: 22 identified
    Context Tags: financial, sensitive_data, camera, location


    About This Analysis

    This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

    App Details

    Developer: Banca Comerciala Romana
    Version: 26.14.19-google (versionCode 2614192)
    Analysis Date: 2026-06-13
    Package: ro.bcr.georgego

    Analysis Limitations

    • Static analysis only (code review without running the app)
    • Based on APK version 26.14.19-google analyzed on 2026-06-13
    • May not reflect server-side security controls
    • Cannot detect all runtime behaviors

    Right of Reply

    Developer not yet contacted