This page aggregates measured, corroborated evidence: donors' iPhones recorded apps contacting this domain, every claim below was reported by separate accepted donations and published under a human verdict (later rows for an approved app inherit its verdict). A contact is a measurement, not an accusation — it does not show what data was sent.
collect.riskid.security
classified as unknown · 2
What our research panel found AI-drafted · human-reviewed
We ask several independent AI models the same question and publish their answers separately — cross-vendor agreement is evidence against fabrication, and disagreement is worth seeing. 2 of 3 models answered, overall confidence high — no answer from gemini (parse). A human reviewed this domain's claims before anything here published.
Anthropic Claude — unknown
I do not know who operates collect.riskid.security; the name and "collect" subdomain suggest a risk/fraud-scoring or device-identification endpoint (common for airline booking and payment flows), but that is inference from the hostname, not verified ownership. Even under that reading, the app already declares collecting and sharing Device or other IDs, payment info, and identity fields, so nothing here clearly implies a flow the label omits.
OpenAI — unknown
The ownership and purpose of collect.riskid.security are not provided, so its role is ambiguous. The app declares collecting and sharing device identifiers and other relevant data types, so this contact is not clearly undisclosed.
Apps measured contacting this domain
| App | Label gap | Donations | Contacts | Seen |
|---|---|---|---|---|
| Allegiant | — | 4 | 4 | 2026-07-28 → 2026-07-29 |
The corpus grows one report at a time: donate your App Privacy Report — anonymous by design.
Think something here is wrong?
Evidence and research improve when people push back. Tell us what to re-check — a misattributed domain, an outdated classification, a claim about your own app — and a human will review it. Responses can take up to 30 days.