# Security & Privacy Scorecard

## Yoti - your digital identity

### App Details

- Package: com.yoti.mobile.android.live
- Developer: Yoti
- Platform: android
- Scan date: 2026-09-10T21:58:16.713822Z

## What This App Collects

The code sends precise location to Yoti; credentials to Yoti, Yoti devicepubapi_v1, Yoti (attrpubapi_v1 attribute service), Yoti (backuppubapi_v1) and 2 other recipients; authentication tokens to Yoti, Yoti (devicepubapi_v1), Yoti pushpubapi_v1 and Yoti user-profile API; and government ID to Yoti. Another 11 data points are sent out to other third parties.

Other findings record data the code reads on the device and data arriving from a server.

## Can This Be Trusted

Yes, on the evidence available.

None of the findings recorded rises to the level of putting a user at risk. Some are at medium severity or above. The rest are lower severity, described in full in the detailed findings. They fall mostly under Network Security, Privacy and Code Security.

## Scores

- Overall: 81/100
- Security: 80/100. Held down by how the app talks to servers and by how the app is put together.
- Privacy: 82/100. Held down by the amount collected and by how little of it is recorded as consented to.
- Data Security: 89/100
- Network Security: 85/100
- Code Safety: 83/100
- Data Collection: 83/100
- Data Sharing: 93/100
- User Control: 82/100
- Permission Usage: 96/100

## How This Was Checked

Much of the checking planned for this app did not finish.

Some of it was set aside before it began, and the code in its scope is left out of this page.

The app package was taken from the store and decompiled to source. Agents map the app from the components it declares and the class that runs at launch, following what those paths reach, and ask of each part which third-party SDKs are called there, what those SDKs receive, and whether a consent step is on the same path as the data. The code is checked against advisories recorded from earlier CITT scans.

The most serious findings are then re-examined by a second set of reviews that re-read the cited code from the app itself and argue against each one. A finding is kept when each of those attempts fails, and what survives is what the reports describe.

This page states the findings in plain language. The detailed report contains the technical detail, with credential-shaped values masked.

## Method and Limitations

Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

## About This Analysis

This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.
