Competitive security assessment · revision 1
Twenty-four security capabilities, scored 0–100 against HSBC, Revolut, Monzo, PayPal and Coinbase Wallet. Heaven leads decisively on the controls that live inside the app — and is beaten everywhere protection comes from a banking licence rather than from code.
Verified 11 August 2026 · re-scored every Monday against Heaven's source and the competitors' published posture
85.7%
Heaven's mean across the 18 in-app capabilities. Nearest rival: Revolut at 72.4%.
70.1%
Fourth of six once deposit protection, licensing and redress are counted. HSBC leads at 78.3%.
9 / 24
Plus 2 shared first places — 11 of 24 at or above every rival, and 11 of the 18 in-app ones.
Grouping the capabilities shows the shape of the result far better than a single average does. Heaven does not lose evenly — it wins two arenas outright by wide margins and loses one almost completely.
Sign-in, MFA, device binding, integrity checks, behavioural signals.
Step-up auth, limits, programmable rules, risk scoring, cooling-off, intent decoding.
Local storage, screen capture blocking, TLS pinning, tamper-evident audit trail.
Self-custody, duress protection, sovereign identity verification.
Deposit guarantees, licensing, reimbursement, staffed fraud desks, recovery, certification.
Every capability, scored 0–100. A gold rail on the left marks a row Heaven wins outright; bold marks the leader in each row.
Swipe to compare all six
| Capability | Heaven | HSBC | Revolut | Monzo | PayPal | Coinbase |
|---|---|---|---|---|---|---|
| Identity & device trust | ||||||
| Biometric / passkey sign-in | 85 | 90 | 88 | 85 | 90 | 80 |
| MFA depth — TOTP, push, recovery codes | 80 | 90 | 80 | 70 | 85 | 75 |
| Device binding & authorised-device registry | 90 | 85 | 85 | 80 | 70 | 60 |
| Device-integrity checks (jailbreak, root, debugger) | 85 | 90 | 85 | 75 | 70 | 55 |
| Behavioural biometrics | 80 | 85 | 70 | 50 | 70 | 30 |
| Transaction defence | ||||||
| Per-transaction step-up authentication | 95 | 85 | 80 | 70 | 65 | 60 |
| User-set spending limits | 95 | 70 | 85 | 75 | 50 | 40 |
| Programmable spending rules | 95 | 40 | 65 | 55 | 25 | 20 |
| Real-time risk scoring shown to the user | 85 | 80 | 85 | 75 | 75 | 45 |
| Cooling-off hold on a first send to a new payee | 95 | 70 | 75 | 65 | 30 | 20 |
| Pre-authorisation clarity / intent decoding | 90 | 70 | 70 | 70 | 60 | 80 |
| Platform hardening | ||||||
| Encrypted local storage | 78 | 90 | 90 | 88 | 85 | 85 |
| Screenshot & screen-record blocking | 90 | 85 | 80 | 70 | 60 | 40 |
| TLS certificate pinning | 35 | 95 | 90 | 90 | 90 | 80 |
| Tamper-evident audit trail | 90 | 95 | 90 | 88 | 88 | 60 |
| Sovereignty & privacy | ||||||
| Self-custody / seizure resistance | 95 | 20 | 20 | 20 | 15 | 95 |
| Duress & stealth protection | 95 | 0 | 10 | 20 | 0 | 30 |
| Sovereign KYC & data minimisation | 85 | 55 | 55 | 55 | 50 | 50 |
| Institutional protection & redress | ||||||
| Deposit protection (FSCS or equivalent) | 0 | 100 | 90 | 100 | 40 | 0 |
| Regulated licence & supervision | 25 | 100 | 90 | 95 | 85 | 30 |
| Fraud reimbursement & payment reversal | 5 | 95 | 85 | 90 | 90 | 0 |
| Staffed 24/7 fraud operations | 20 | 95 | 90 | 90 | 80 | 40 |
| Credential & account recovery | 70 | 95 | 90 | 90 | 90 | 65 |
| Independent certification (SOC 2, ISO 27001, pentest) | 20 | 100 | 95 | 90 | 95 | 85 |
| Mean across all 24 | 70.1 | 78.3 | 76.8 | 73.2 | 64.9 | 51.0 |
| Mean across the 18 in-app capabilities | 85.7 | 71.9 | 72.4 | 66.7 | 59.9 | 55.8 |
Every other loss follows from Heaven not being a bank. These three do not — they are code, and closing them lifts the all-24 mean from 70.1 to roughly 76.
The pinning service is fully written, but all six fingerprints read PLACEHOLDER_…, so release builds validate nothing. A debug-only banner flags it in development and is compiled out of release. Populating the pins moves this capability from 35 to roughly 90 — the single largest available gain.
The PIN hash and recovery codes go to secure storage correctly. Stealth-mode configuration, spending limits, spending rules, time-locks and risk state go to SharedPreferences, which is unencrypted on both platforms. An attacker with filesystem access can read the decoy balance and every configured limit — and stealth mode only works if the decoy is secret.
The client is complete and waits on a challenge document, but the Cloud Function that writes the challenge, pushes the notification and records approval is still a TODO. Until it ships, MFA depth rests on TOTP and recovery codes alone.
Heaven's scores are derived from reading the codebase — the COVR security services, the authentication and MFA layer, the KYC flow, the native device-integrity bridges, the audit logger and the storage wrappers. Where a capability is written but not yet live, it is scored as not live: that is why certificate pinning sits at 35 rather than 90.
Comparison scores reflect the publicly documented security posture of each provider as of the assessment date, drawn from published product documentation, regulatory status and standard industry practice. They are not derived from source access, so they carry more uncertainty than Heaven's column — and incumbents generally under-document their controls, so if anything these numbers are conservative.
The scale is capability strength, not risk. A capability that does not apply to a provider's model is scored on the nearest equivalent protection rather than marked absent — a bank transfer has no calldata to decode, so pre-authorisation clarity scores what the customer actually understands before committing.
Self-custody is scored as seizure resistance, which is the security property it delivers. Its cost — no reversal, no deposit guarantee, no recovery of a lost key — is scored separately in the institutional arena, so the model is credited and charged for the same choice exactly once.