# Security & Privacy Scorecard

## Eneco

**Version:** 2026.0224.0 (Build 100007975)
**Scan Date:** 2026-03-06
**Package:** com.afrogleap.eneco.myeneco

## What This Means for You

Several analytics tools, including ContentSquare and Heap Analytics, record how users tap and navigate through the app to build a picture of in-app behavior. Account and billing details may not be fully protected, which could affect sensitive data. Users retain reasonable control over personal data settings.

## Recommendation: Use With Caution

**Best For:** Managing your home energy contract
**Avoid If:** Minimal in-app behavior tracking is a priority

## Key Findings

**Data Security** - 2 findings (1 critical, 1 high)

**Network Security** - 4 findings (1 high, 2 medium, 1 low)

**Code Safety** - 0 findings

**Privacy** - 3 findings (1 critical, 2 medium)

## Privacy Concerns

### What Data is Collected

Eneco collects account and billing details, energy usage data, device identifiers, and records of how users interact with the app. Behavioral analytics services capture the specific screens users visit and actions taken within the app to build a profile of in-app activity.

### Third-Party Data Sharing

Usage and behavioral data are shared with the following third-party services:

- **Urban Airship** - push notification delivery
- **ContentSquare** - detailed in-app behavior recording
- **Dynatrace** - app performance monitoring
- **Firebase** - analytics and crash reporting
- **Okta** - identity and sign-in services
- **Usabilla** - in-app feedback collection
- **Heap Analytics** - behavioral analytics and interaction tracking
- **Enode LinkKit** - smart energy device integration
- **Google Play Services** - core platform services
- **GrowthBook** - feature experimentation

## Understanding the Scores

| Category | Score |
|---|---|
| Security | 52/100 |
| Privacy | 68/100 |
| Data Security | 48/100 |
| Network Security | 86/100 |
| Code Safety | 70/100 |
| Data Collection | 62/100 |
| Data Sharing | 96/100 |
| User Control | 72/100 |

## Positive Security Features

- None identified in this version of the app.

## Areas for Improvement

- Account and billing data could be stored with stronger protections on the device. If a phone were accessed without authorization, this information would be more exposed than expected.
- Multiple analytics providers collect detailed records of in-app behavior with limited visibility into how to opt out. Clearer controls would give users more say over behavioral profiling.
- Some data in transit between the device and Eneco's servers uses protection settings that could be strengthened to reduce the chance of interception on untrusted networks such as public Wi-Fi.

---

## About This Analysis

This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect security and privacy practices observed at the time of scanning and may not capture all behaviors that occur at runtime.

### App Details

| Field | Value |
|---|---|
| App Name | Eneco |
| Package ID | com.afrogleap.eneco.myeneco |
| Version | 2026.0224.0 (Build 100007975) |
| Scan Date | 2026-03-06 |
