# Can I trust Raiffeisen Bank SK?

Raiffeisen Bank SK for Android, version 2.5.0 (build 341) (scanned 16 September 2026) is labelled unTRUSTED, with a score of 64 out of 100. This app did not meet two or more trust checks, has a critical issue in one, or has a red flag. The scan names 14 third-party services: Firebase Crashlytics, Firebase Messaging (FCM), Firebase Installations, Firebase Sessions, Firebase Remote Config, Google ML Kit (Barcode Scanning), Google ML Kit (Text Recognition), Google Play Services (TapAndPay / Google Pay), Google Play Services (Maps), OkHttp3, BouncyCastle, Radaee PDF Reader, Lottie and DexGuard. It recorded 9 findings rated low or higher across 5 categories, 8 of them rated medium or higher. A static scan shows what the app's code and manifest contain; the app's network traffic needs a capture of the running app.

- Package: `sk.raiffeisen.ib.androidwrapper`
- Platform: Android
- Version: 2.5.0 (build 341)
- Google Play version: 2.5.0, the scanned version (checked 5 October 2026)
- Scanned build downloaded: 16 September 2026
- Scanned: 16 September 2026
- Label and score: unTRUSTED, 64 of 100 (criteria: https://canitrustthat.com/methodology)

## Trust checks

- Secure by Design: An item rated high or above is open
  - Security gaps detected
  - This check looks for security issues at high severity or above in the code of this build, and at least one was recorded. Issues of this kind include a credential or token another app on the device can reach, sensitive data stored without protection, and network paths that expose information in transit.
- Data Minimization: One criterion not met
  - Tracking lacks clear disclosure
  - This build contains analytics or attribution code written to send data to companies other than the developer. No consent step was found before that code runs, and the app's disclosures do not describe the collection in full. Tracking by itself is ordinary; what this check reports is the combination of collection, recipient and absent disclosure.
- Manifest Mismatch: One criterion not met
  - Disclosure incomplete or contradicted
  - The check compares the app's privacy disclosures against what the code does, and at least one claim did not match in this build. Mismatches of this kind include a data category collected but not disclosed, a recipient the disclosure omits, and an identifier attached to data the disclosure describes as anonymous.
- User Control: Strong
  - No lock-in
  - The check looks for a way to export the data an account has accumulated and a way to delete the account itself. In this build, either both were found, or the app has no account of its own and keeps its data on the device. For an app without an account, the developer has no server-side copy to export or delete, and deleting the app removes the data in its own storage.
  - The app is a portal to a regulated banking service operating under European banking law and GDPR, which grant users the right to access, obtain, and delete their financial data. The app stores no proprietary data formats on the device and creates no app-specific barriers to leaving the service.

## Summary

- Avoid if: Users who primarily bank on public Wi-Fi
- What it means for you: No advertising or behavioral tracking SDKs are bundled in build 341. Authentication keys and barcode scans remain on-device. Firebase Crashlytics is present for crash reporting; the code encrypts push notification content before handing it to the Firebase SDK, so Firebase does not see message content. The code for some banking requests may apply less protection than expected on public Wi-Fi.
- Main concern: WebView accepts any SSL certificate, enabling trivial banking session interception
- The developer's description: The Raiffeisen Bank application allows you to access the bank's website and Internet Banking using a mobile device. Features include account information, payments, standing orders, barcode/QR/IBAN scanning, card management, biometric login, and ATM locator.

## Strengths

- Login sessions are protected by hardware-backed biometric keys stored in AndroidKeyStore that never leave the secure element
- No advertising networks or behavioral tracking SDKs are present
- All traffic uses HTTPS with cleartext HTTP blocked at the OS level, including inside the banking WebView
- App data cannot be extracted via ADB backup or Android Cloud Backup
- Barcode and document scanning (ML Kit) processes data on-device only with no external data transmission
- The code encrypts push notification payloads end-to-end before handing them to the Firebase SDK, so the Firebase SDK is given only encrypted payloads
- Runtime integrity protection detects tampering and terminates the app before any UI or data is loaded

## What the app contains

- Firebase Crashlytics
- Firebase Messaging (FCM)
- Firebase Installations
- Firebase Sessions
- Firebase Remote Config
- Google ML Kit (Barcode Scanning)
- Google ML Kit (Text Recognition)
- Google Play Services (TapAndPay / Google Pay)
- Google Play Services (Maps)
- OkHttp3
- BouncyCastle
- Radaee PDF Reader
- Lottie
- DexGuard

## Libraries

- Lottie
- Datatransport
- Google Sign-In 12451000
- Google Play Services 12451000
- Material Components
- Gson
- Firebase 12451000
- Google ML Kit
- OkHttp 5.3.2
- Okio
- RxJava 2
- BouncyCastle
- Kotlin Coroutines
- Kotlin Serialization

## Corrections

No correction is published for this app.

## Method and limits

Static analysis: the decompiled code, manifest and resources of this build, read file by file. Network traffic at run time is established by a capture of the running app.

Build SHA-256: `3345c0148fbd4c9ccbdf07611cd32f7e0e4652f881663b4ef16eb5a3ce6c74cd`
Rule pack: `citt-ruleset-2026-08-v1`

HTML page: https://canitrustthat.com/apps/sk.raiffeisen.ib.androidwrapper
