All data transmission happens over secure communication channels (over HTTPS).
The app does not have any issues with its authentication APIs.
The app's backend servers endpoints can be modified by a remote attacker to retrieve PII.
The app allows the users to edit their information in the app.