Avanza Security & Privacy Scorecard

Android

68
Overall trust score
Acceptable
65
Security
75
Privacy

App usage and crash data is shared with Firebase, including diagnostics that help the developer but also feed Google's infrastructure. Authentication flows through BankID and Trustly, third-party services that handle user identity and payment data. Some data is stored in ways that carry moderate risk if the device is compromised.

Best for

Swedish investors comfortable with standard crash reporting

Findings

  • 1 critical
  • 5 high
  • 0 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Encryption Fallback to Plaintext SharedPreferences
  • Arbitrary URL Scheme Launching via JavaScript Interface
  • Session Tokens Logged to Metrics Backend

Top privacy issues

  • Clipboard Access via JavaScript Without Permission
  • Firebase Crashlytics PII Leakage Risk
  • WebView Cookie Storage Unencrypted

Full analysis

Avanza

Version: 5.127.0 (Build 1027)
Scan Date: 2025-12-18
Package: se.avanzabank.androidapplikation

What This Means for You

App usage and crash data is shared with Firebase, including diagnostics that help the developer but also feed Google's infrastructure. Authentication flows through BankID and Trustly, third-party services that handle user identity and payment data. Some data is stored in ways that carry moderate risk if the device is compromised.

Recommendation: Use With Caution

Best For: Swedish investors comfortable with standard crash reporting

Key Findings

Data Security - 9 findings (3 high, 5 medium, 1 low)

Network Security - 1 finding (1 medium)

Code Safety - 0 findings

Privacy - 3 findings (1 high, 1 medium, 1 low)

Privacy Concerns

What Data is Collected

Avanza collects usage and behavioral data through Firebase analytics, capturing how users interact with the app and which features they use. Crash and diagnostic reports are sent to Firebase Crashlytics when the app encounters errors. Device identifiers and session activity are included in this collection.

Third-Party Data Sharing

Data is shared with three external services:

  • Firebase (Google) - receives crash reports, usage patterns, and app diagnostics
  • BankID - receives user identity information during authentication flows
  • Trustly - receives payment-related data when users use connected payment features

Understanding the Scores

Category Score
Overall Security 65/100
Overall Privacy 75/100
Data Security 58/100
Network Security 92/100
Code Safety 72/100
Data Collection 88/100
Data Sharing 78/100
User Control 70/100

Positive Security Features

  • Network communications are well-protected, as reflected in the high Network Security score of 92/100
  • Authentication relies on established Swedish financial identity infrastructure rather than a custom-built login system

Areas for Improvement

  • Certain data stored locally on the device could be better protected against unauthorized access if the device is lost or stolen
  • Options to control or limit data collected about in-app behavior are limited
  • Data flows through multiple third-party services, each applying their own data handling practices outside the developer's direct control

About This Analysis

This scorecard was generated through automated static analysis of the app's code and configuration. Scores reflect the security and privacy practices observed in the analyzed version and may not capture server-side behaviors.

App Details

Field Value
App Name Avanza
Package ID se.avanzabank.androidapplikation
Version 5.127.0 (Build 1027)
Scan Date 2025-12-18
Platform Android

Versions & scan history

ScanDateOverall score
#4 (current) 68/100
#3 72/100
#2 82/100
#1 82/100