Mobile App Risk is Business Risk.
Regulators are watching Enterprise mobile apps. Users demand transparency. Get instant visibility into privacy risks, AI data exposure, dangerous permissions and suspicious network connections across your entire enterprise app portfolio.
Search 2,000+ Enterprise Apps. Know Your Risk in Minutes.
Bank of America Mobile Banking
Bank of America Mobile Banking
Bank conveniently and securely with the Bank of America® Mobile Banking app for U.S.-based checking, savings, credit card, loan and investment accounts.
Manage Accounts
•View account balances and review activity
•Activate or replace credit/debit cards
•Set alerts for important account info
•Manage all accounts, including checking, savings, credit cards, loans and investment accounts
Transfer Money and Pay Bills
•Securely send and receive money with Zelle® using a US mobile number or email address¹
•Transfer funds between your Bank of America and linked Merrill accounts
•Pay bills
Check Deposit
•Take photos of checks to deposit them to your checking or savings account
•Get immediate confirmation that your check is processing²
Erica, Your Virtual Financial Assistant³
•Ask Erica to find transactions, pay bills and more
•Get valuable alerts, and helpful insights
Security
•Set up Touch ID/Face ID®
•If fraudulent activity is suspected on your card, we’ll notify you
•View security center
•With our Mobile Banking Security Guarantee, you’re not liable for fraudulent transactions when reported promptly⁴
Manage Investments with Merrill
•Trade stocks,ETFs,mutual funds
•View up-to-date Market data, news, and quotes
•Send messages and documents securely to your advisor
FICO® Credit Score
•Easily check your FICO® credit score
•View the key factors that affect your score
•Find out about keeping credit healthy
Financial Education and Savings & Budgeting Tools
•Set up and manage savings goals
•Organize and track your spending by category
•View all transactions
•Compare spending against income
•Easily create a budget based on previous spending or from scratch
See the Online Banking Service Agreement at bankofamerica.com/serviceagreement for more information. Mobile carrier message and data rates apply.
¹Zelle transfers require enrollment and must be made from a Bank of America consumer checking or savings account to a domestic bank account or debit card. Recipients have 14 days to register to receive money or the transfer will be canceled. Dollar and frequency limits apply.
²Deposits are subject to verification and not available for immediate withdrawal. Other restrictions apply.
³Erica only listens or speaks when you tap the microphone and retains interactions to optimize your experience. Erica speaks aloud and hears and responds to all voices. Erica is only available in English.
⁴You’re not liable for fraudulent Mobile Banking transactions when you notify the bank within 60 days of the transaction first appearing on your statement and comply with security responsibilities.
Investing involves risk. There is always the potential of losing money when you invest in securities.
Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as MLPF&S or Merrill) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (BofA Corp). MLPF&S is a registered broker-dealer, registered investment adviser, Member SIPC and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc. (MLLA), a licensed insurance agency and wholly owned subsidiary of BofA Corp.
Banking products are provided by Bank of America, NA, and affiliated banks, Members FDIC and wholly-owned subsidiaries of Bank of America Corporation.
Investment products
•Are Not FDIC Insurance
•Are Not Bank Guaranteed
•May Lose Value
All features may not be available in iPad and may only be available for certain account types
Zelle® and the Zelle® related marks are wholly owned by Early Warning Services, LLC and are used herein under license
iPhone, iPad, Touch ID and Face ID are registered trademarks of Apple®, Inc
Bank of America related trademarks are trademarks of Bank of America Corporation
Bank of America, NA Member FDIC
©2025 Bank of America Corporation
Bank of America Mobile Banking
Package ID
284847138
Version
25.09.02
Developer
Bank of America
Category
Finance
Store Rank
15
App Store Link
View in App StoreDeveloper Privacy Policy
Privacy PolicyObservations Summary:
Permissions Observations
DETECTEDPermissions defined by Apple and Google as dangerous have been observed.
Observed During Analysis
- The app is requesting access to the user’s media library.
- The app needs access to Bluetooth.
- + 12 more
- The app is requesting the ability to connect to Bluetooth peripherals.
- The app is requesting access to their calendar data.
- The app is requesting access to the device’s camera.
- The app is requesting access to the user’s contacts.
- The app is requesting the ability to authenticate with Face ID.
- The app is requesting access to the user’s location information at all times.
- The app is requesting access to the user’s location information while the app is running in the foreground.
- The app is requesting access to the device’s microphone.
- The app is requesting add-only access to the user’s photo library.
- The app is requesting access to the user’s photo library.
- The app is requesting to send user data to Siri.
- The app is requesting to send user data to Apple’s speech recognition servers.
- show less
- See Your App’s Risk Profile
Why Permissions Matter
If not managed properly, dangerous permissions can permit malicious access to sensitive data, and device features.
Privacy Declarations Observations
DISCREPANCY DETECTEDA discrepancy in the declarations was observed, indicating there are conflicts or omissions in the app or component declarations.
Observed During Analysis
- Missing iOS Privacy Manifest
- Missing Accessed API Types Declaration
- + 1 more
- Missing Privacy Tracking Declaration
- show less
- See Your App’s Risk Profile
Why Privacy Declarations Matter
Declarations matter because they provide transparency on how apps collect and use sensitive data. iOS requires Privacy Manifest declarations, while Android requires Data Safety disclosures and manifest permissions.
Sensitive Data Collection and Sharing Observations
SENSITIVE INFO FOUNDThis app collects, stores, or shares information that is often designated as sensitive and private.
Observed During Analysis
- Identifier for Vendor (IDFV)
- ZIP Code
- See Your App’s Risk Profile
Why Data Collection and Sharing Matters
If not managed properly private data can expose enterprises, customers, employees and partners to breach and compliance violations.
Network Connections Observations
DETECTEDNetwork analysis has detected communication with external servers and data transfer patterns.
Observed During Analysis
Connected Hostname:
- adobe.com
- akamai.com
- + 2 more
- bankofamerica.com
- microsoft.com
- show less
Server Locations:
- Boydton, Virginia, US
- Charlotte, North Carolina, US
- + 2 more
- Lehi, Utah, US
- Mount Prospect, Illinois, US
- show less
- See Your App’s Risk Profile
Why Network Connections Matter
Uncontrolled communication with external servers by an employee-used app could expose sensitive business data to unauthorized third parties. This unauthorized access can lead to data breaches, regulatory non-compliance, and damage to your business's reputation and financial standing.
AI Observations
NONE DETECTEDNone detected. Further analysis recommended.
- See Your App’s Risk Profile
Why AI Matters
AI features can process sensitive data in unexpected ways, potentially exposing proprietary information or creating liability.
NowSecure provides detailed risk assessments for millions of mobile apps. We Can Help Secure Your App.
All trademarks, logos, and brand names are the property of their respective owners. All company, product, and service names used in this website are for identification purposes only. Use of these names, trademarks, and brands does not imply endorsement.
MARC App Directory