<!-- TRUSTED_VERDICT_HEADER -->
# Did not meet TRUSTED criteria

This build did not satisfy all of CITT's published criteria for the TRUSTED mark. The full criteria and this app's results are shown below.

## Trust Pillars

- **Secure by Design**: Not met. Did not meet one criterion in this area.
- **Data Minimization**: Not met. Did not meet one criterion in this area.
- **Manifest Mismatch**: Not met. Did not meet one criterion in this area.
- **User Control**: Strong. Strong result in this area.
- **Truly Local**: Not applicable. Does not apply to this app.
- **Child-Safe**: Not applicable. Does not apply to this app.

---
<!-- /TRUSTED_VERDICT_HEADER -->

# Security & Privacy Scorecard

## Expensify - Travel & Expense

## What This Means for You

In-app interaction and session data is shared with FullStory, Firebase Analytics, and Urban Airship. Financial account connections are managed through Plaid, and identity verification through Onfido. The app also bundles Group-IB fraud detection and Sentry error reporting.

## Recommendation: Use With Caution

**Best For:** Business travelers managing expense reports

**Avoid If:** Users preferring financial activity not logged by analytics

## Method and Limitations

Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

## Key Findings


**Data Security:** 1 finding (1 medium)

**Network Security:** 2 findings (1 medium, 1 low)

**Code Security:** 4 findings (1 high, 2 medium, 1 low)

**Privacy:** 1 finding (1 high)

**Third-Party Risk:** 1 finding (1 medium)

## Privacy Concerns

### What Leaves the Device

The build links FullStory, an in-session recording service. Session interactions and screen content may be shared with FullStory's platform; runtime behavior was not tested. Firebase Analytics is linked and behavioral event data may be shared with Google's analytics infrastructure; runtime flows were not observed. Urban Airship is linked for push notification delivery and device identifiers may be shared with Airship's platform; runtime data flows were not tested. Plaid Link is bundled for financial account connection flows and account access data may be shared with Plaid's infrastructure; runtime flows were not observed. Onfido is bundled for identity verification and personal identity documents may be shared with Onfido's servers; runtime behavior was not tested. Group-IB Fraud Hunting Platform SDK is linked and device signals may be shared with Group-IB's fraud analysis infrastructure; runtime transmission was not observed. Sentry React Native is linked and error report data may be shared with Sentry; runtime behavior was not tested.

### What Stays on the Device

The build includes Realm for local database storage, keeping structured data under local device control. Google MLKit is linked for on-device machine learning processing. Lottie handles animation rendering locally. React Native with the Hermes engine handles application logic on the device. Data processed through these components does not leave the device through those libraries.

### Third-Party Data Sharing

The build integrates analytics and session recording libraries from FullStory and Firebase Analytics. Push notification delivery is provided through Urban Airship. Financial account connection functionality is provided through Plaid Link. Identity verification functionality is provided through Onfido. Fraud detection functionality is provided through the Group-IB Fraud Hunting Platform SDK. Error reporting is provided through Sentry. Navigation and mapping is provided by Mapbox. Real-time event delivery is provided by Pusher. Authentication is provided by Firebase Auth and Google Sign-In.

## Understanding the Scores

**Security: 72/100 (Solid)**
CITT rates this build's overall security posture as solid. Network security contributes positively to this score, while the data security sub-score placed the overall figure in this range.

**Privacy: 62/100 (Use With Caution)**
CITT rates this build's privacy posture as use with caution. The build links multiple analytics, session recording, and third-party data service libraries, which contributes to this rating.

**Data Security: 58/100 (Use With Caution)**
CITT rates this build's data security as use with caution. A medium-severity finding in this category contributed to this score.

**Network Security: 80/100 (Trustworthy)**
CITT rates this build's network security posture as trustworthy. Network-layer protections present in this build contributed to this strong rating.

**Code Safety: 72/100 (Solid)**
CITT rates this build's code safety posture as solid. One high-severity finding alongside medium and low findings in the code security category placed this score in the solid range.

**Data Collection: 60/100 (Use With Caution)**
CITT rates this build's data collection scope as use with caution. The build links multiple analytics services and a session recording library, contributing to this score.

**Data Sharing: 62/100 (Use With Caution)**
CITT rates this build's data sharing practices as use with caution. The build links services from multiple third-party providers across analytics, identity verification, fraud detection, and financial account management categories.

**User Control: 65/100 (Use With Caution)**
CITT rates this build's user control provisions as use with caution. The extent to which users can adjust or limit data flows from the various integrated services could not be confirmed from static analysis alone; runtime testing was not performed.

## Positive Security Features

No positive security practices were identified in the analyzed build.

## Areas for Improvement

- The data security sub-score of 58 reflects a medium-severity finding in how stored data is handled in this build. Improving data storage practices would raise this score into the solid range.
- The breadth of analytics, session recording, and behavioral profiling services integrated in this build means financial activity and in-app behavior may be logged by multiple third parties. The extent of user opt-out controls could not be confirmed from static analysis; runtime testing was not performed.
- The code security category contains one high-severity finding alongside additional medium and low findings, indicating room to strengthen safe coding practices in this build.

---

## About This Analysis

### App Details

| Field | Value |
|-------|-------|
| App | Expensify - Travel & Expense |
| Package ID | org.me.mobiexpensifyg |
| Version | 9.4.0-7 (versionCode 509040007) |
| Scan Date | 2026-08-11 |
| Analysis Method | Static analysis |

## Right of Reply

Developer not yet contacted

_Analyzed 2026-08-11 · ruleset citt-ruleset-2026-08-v1 · artifact binary not retained_
