Avanza Security & Privacy Scorecard
Android
App usage and crash data is shared with Firebase, including diagnostics that help the developer but also feed Google's infrastructure. Authentication flows through BankID and Trustly, third-party services that handle user identity and payment data. Some data is stored in ways that carry moderate risk if the device is compromised.
Best for
Swedish investors comfortable with standard crash reporting
Findings
- 1 critical
- 5 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Encryption Fallback to Plaintext SharedPreferences
- Arbitrary URL Scheme Launching via JavaScript Interface
- Session Tokens Logged to Metrics Backend
Top privacy issues
- Clipboard Access via JavaScript Without Permission
- Firebase Crashlytics PII Leakage Risk
- WebView Cookie Storage Unencrypted
Full analysis
Avanza
Version: 5.127.0 (Build 1027)
Scan Date: 2025-12-18
Package: se.avanzabank.androidapplikation
What This Means for You
App usage and crash data is shared with Firebase, including diagnostics that help the developer but also feed Google's infrastructure. Authentication flows through BankID and Trustly, third-party services that handle user identity and payment data. Some data is stored in ways that carry moderate risk if the device is compromised.
Recommendation: Use With Caution
Best For: Swedish investors comfortable with standard crash reporting
Key Findings
Data Security - 9 findings (3 high, 5 medium, 1 low)
Network Security - 1 finding (1 medium)
Code Safety - 0 findings
Privacy - 3 findings (1 high, 1 medium, 1 low)
Privacy Concerns
What Data is Collected
Avanza collects usage and behavioral data through Firebase analytics, capturing how users interact with the app and which features they use. Crash and diagnostic reports are sent to Firebase Crashlytics when the app encounters errors. Device identifiers and session activity are included in this collection.
Third-Party Data Sharing
Data is shared with three external services:
- Firebase (Google) - receives crash reports, usage patterns, and app diagnostics
- BankID - receives user identity information during authentication flows
- Trustly - receives payment-related data when users use connected payment features
Understanding the Scores
| Category | Score |
|---|---|
| Overall Security | 65/100 |
| Overall Privacy | 75/100 |
| Data Security | 58/100 |
| Network Security | 92/100 |
| Code Safety | 72/100 |
| Data Collection | 88/100 |
| Data Sharing | 78/100 |
| User Control | 70/100 |
Positive Security Features
- Network communications are well-protected, as reflected in the high Network Security score of 92/100
- Authentication relies on established Swedish financial identity infrastructure rather than a custom-built login system
Areas for Improvement
- Certain data stored locally on the device could be better protected against unauthorized access if the device is lost or stolen
- Options to control or limit data collected about in-app behavior are limited
- Data flows through multiple third-party services, each applying their own data handling practices outside the developer's direct control
About This Analysis
This scorecard was generated through automated static analysis of the app's code and configuration. Scores reflect the security and privacy practices observed in the analyzed version and may not capture server-side behaviors.
App Details
| Field | Value |
|---|---|
| App Name | Avanza |
| Package ID | se.avanzabank.androidapplikation |
| Version | 5.127.0 (Build 1027) |
| Scan Date | 2025-12-18 |
| Platform | Android |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #4 (current) | 68/100 | |
| #3 | 72/100 | |
| #2 | 82/100 | |
| #1 | 82/100 |