YENRA MOBILE APP ADOPTION REVIEW Guide: https://yenra.com/mobile-security/ Prepared September 12, 2026. Editable planning aid; not a security certification. Use a test account and invented records. Keep secrets and confidential reports in approved storage; reference them here rather than copying their contents. INSTRUCTIONS 1. Define one permitted work task and the data it needs. 2. Observe the task and permissions using the exact version under review. 3. Record supplier claims separately from observed behavior and assessment evidence. 4. Assign unresolved questions and approve only a stated use and configuration. App / publisher / official distribution URL: App version / OS version / device model / review date: Business owner / intended users: Task and required data fields: Permission / purpose / observed prompt / choice / task result: Data stored locally / sent to service / shared with other providers: Retention and deletion documentation URL / checked date: Account administrator / recovery method / removal test: Assessment provider / report date / app and backend versions / scope: Excluded components / unresolved findings / remediation evidence: Observation / supplier claim / independent evidence (keep distinct): Unanswered question / owner / required evidence / due date: Decision: approve defined use / limited pilot / further assessment / reject Accepted data types / settings / version / conditions: Decision owner / date: Review triggers (permissions, data recipients, identity, ownership, OS support): FICTIONAL EXAMPLE Task: submit a receipt photograph using a test account. Observation: camera access supports submission; the task also succeeds with background location disabled. Open question: supplier must explain the background-location request. Limit: this test establishes task behavior, not the app's complete security.