# Security & Privacy Scorecard

## Centraal Beheer

**Version:** 7.49.0  
**Platform:** Android  
**Scan Date:** January 25, 2026

## What This Means for You

Usage patterns and in-app behavior are tracked by Firebase, Google Analytics, and Microsoft App Center. A third-party firm, Celebrus Technologies, also collects user activity data. Account and policy information is transmitted, and some protections around how that data travels could be stronger.

## Recommendation: Use With Caution

**Best For:** Centraal Beheer customers comfortable with standard

## Key Findings

**Data Security** - 3 findings (1 critical, 2 medium)

**Network Security** - 5 findings (1 critical, 1 high, 2 medium, 1 low)

**Code Safety** - 0 findings

**Privacy** - 5 findings (1 critical, 2 high, 1 medium, 1 low)

## Privacy Concerns

### What Data is Collected

The app collects behavioral and usage data across multiple channels. Firebase Analytics and Google Analytics record how users navigate and interact with features. Microsoft App Center collects session and diagnostic data. Celebrus Technologies and Usabilla gather additional interaction and behavioral signals. Sitecore Content Hub may process content-related usage information tied to the user session.

### Third-Party Data Sharing

User activity data flows to at least nine external services. Google Tag Manager coordinates data routing across Google's advertising and analytics ecosystem. Celebrus Technologies receives behavioral profiles that extend beyond the app's core insurance functions. Usabilla shares feedback and interaction data with its parent organization. Firebase Crashlytics and Firebase Performance Monitoring transmit diagnostic information to Google's infrastructure.

## Understanding the Scores

| Category | Score |
|---|---|
| Security | 65/100 |
| Privacy | 55/100 |
| Data Security | 70/100 |
| Network Security | 65/100 |
| Code Safety | 75/100 |
| Data Collection | 50/100 |
| Data Sharing | 45/100 |
| User Control | 60/100 |

## Positive Security Features

- The app uses well-maintained, industry-standard networking libraries (OkHttp, Retrofit) that receive regular security updates from their maintainers.
- Apollo GraphQL provides a structured approach to data requests, which limits the surface area for unintended data exposure during server communication.

## Areas for Improvement

- The protections governing how account and policy data travels between the app and servers have gaps that could be closed with stronger safeguards.
- Behavioral data is routed to a large number of third-party organizations, several of which operate beyond the user's direct awareness or control.
- The app provides limited built-in options for users to review or restrict what information is collected during normal use.

---

## About This Analysis

This scorecard is based on automated static analysis of the app's compiled code and configuration. Scores reflect the app's state at the time of the scan and may change as the app is updated.

### App Details

- **App Name:** Centraal Beheer
- **Package ID:** nl.centraalbeheer.centraalbeheerapp
- **Version:** 7.49.0
- **Scan Date:** January 25, 2026
