If you trade on Betfair Exchange and you’re considering a third-party tool, one question matters more than features or speed: Can you trust it with your account? Is BetOnDroid safe to use?
Hijacked accounts, leaked credentials are real concerns in the Android trading space. They are also a big reason most traders stick with desktop tools they already know.
This post explains the security architecture behind BetOnDroid: how authentication works, what Betfair’s certification covers, and what we cannot guarantee.
Two Ways to Sign In – One of Them Cannot See Your Password at All
BetOnDroid offers two sign-in options, shown as tabs on the login screen:
1. via BetOnDroid (default). The user enters their Betfair username and password directly into the app. If “Remember me” is selected, credentials are stored locally on the device, encrypted with AES-128 (the minimum required by Betfair certification). Additional 2FA auth is supported through a checkbox. This is the original login mode and remains the default because it is faster – no extra resources loading and no extra round-trips on slow connections.
2. via Betfair Web. No credential fields appear in the app at all. When the user taps “Sign in,” BetOnDroid opens an embedded WebView pointed at Betfair’s official sign-in page (identitysso.betfair.com). The user enters their credentials on Betfair’s own page – the same page they would see on betfair.com. After successful authentication, Betfair returns only a newly created session token to the app. The application never sees the username or password – not even temporarily, not even in encrypted form.

The second option is for users who want maximum isolation between the app and their Betfair credentials. It is handled entirely by Betfair’s own login page – BetOnDroid is not involved in that flow at all.
This dual-login design is a deliberate architectural choice: users who prioritise speed can use the direct login, and users who prioritise isolation can use the web flow. Both passed Betfair’s certification.
Let’s look Betfair’s Security Review. Is it safe for everyday use?
Before any third-party application is allowed to interact with the Betfair Exchange API, it has to pass Betfair’s Vendor Certification. This is not a self-assessment form – Betfair’s team reviews the application against a published security checklist.
A few of the requirements that matter most for users:
- The vendor must never see your username or password when using the web sign-in flow. Authentication has to go directly between the device and Betfair’s servers.
- No proxies between the app and the API. All communication must go directly to Betfair’s API over a secure HTTPS channel. Apps that funnel traffic through middleware are excluded.
- Stored credentials, if any, must be encrypted with AES (minimum 128-bit key length). Local storage requires explicit user opt-in — the default is “do not save.”
- The application key must be obfuscated so it cannot be extracted, reverse engineered and abused.
- A logout function is mandatory so users can end their session cleanly.
The review is not a one-time check. Betfair re-runs verification on every major update — for example, when the authentication flow changes, when the app moves to a new API version, or when changes affect the Vendor API integration. This means continuous oversight rather than a single approval.
Listed in the Official Betfair App Directory
Passing certification is one part of the process. Being listed on the official Betfair App Directory is the public confirmation that the app is current, certified, and recommended by Betfair.
If an application is not in that directory, there is no formal way to verify its certification status. This is the fastest check anyone can do before installing a Betfair-connected Android app: search the App Directory. If it is not there, treat it as untrusted.
” width=”300″ height=”99″ />
A Clean Antivirus Scan
Betfair’s review covers the application’s behaviour against their API. It does not, by design, scan the APK file itself for malware signatures. For that, an independent service is the right tool.
We ran the current BetOnDroid 4.1.8 release through VirusTotal, which checks files against 67 different antivirus engines simultaneously. The result: 0 out of 67 vendors flagged the file as malicious.
This is the same kind of scan Google Play Protect runs in the background when an APK is installed on Android. A clean result here means none of the major antivirus vendors — Kaspersky, ESET, Bitdefender, Microsoft, and dozens of others — recognise any malicious code patterns in the binary.
What About Personal Data?
BetOnDroid does not collect personally identifiable information. Betfair credentials never leave the device. Authentication and trading happen directly between the user’s phone and Betfair’s servers.
The application uses Google Firebase for crash reporting and anonymised performance metrics, which is standard practice for Android development and helps the team fix bugs faster. The full breakdown is available in the Privacy Policy.
What We Cannot Promise
No application — ours or anyone else’s — can claim to be “100% secure.” What we can offer is a list of verifiable facts:
- BetOnDroid offers a web-based login flow in which the application never sees credentials in any form.
- The app passes Betfair’s certification, re-checked on every major release.
- It is listed in the official Betfair App Directory.
- The current build scores 0 detections out of 67 on VirusTotal.
- Credentials goes directly between the user’s device and Betfair, with no third party in between.
This is a higher bar than most third-party Android trading tools meet, and significantly higher than any APK distributed through unofficial mirror sites.
Try It
If the security side checks out, the next question is whether the app does what you need. The fastest way to find out is to install it and try it on a few markets.
Try BetOnDroid — direct from this site, certified build, no Google Play required.
