TRUST CENTER

Security at CashShield

Updated September 11, 2026

CashShield is operated by Xmbroider LLC.

CashShield never receives your bank username or password. Plaid handles institution authentication and returns supported financial data and an access token. CashShield encrypts that token in server-only storage.

Account protection

Data boundaries

Provider verification

CashShield validates Plaid webhook signatures and request-body hashes before queuing synchronization. Stripe webhook signatures are checked against the original request body with a limited timestamp window. Subscription access is reconciled against Stripe’s current records; a browser return link cannot grant Premium access.

Payments and receipts

Stripe hosts payment entry and stores payment-card details. CashShield stores subscription identifiers and status rather than full card numbers. Receipt photos are available only to authenticated members of the household. Gemini processes submitted receipt images to return structured merchant, total, date, and item data.

What users can do

Use a unique password, protect your email and phone accounts, keep a backup verification phone, review household membership, disconnect old institutions, and never share verification codes. Review receipt extractions and forecasts before relying on them.

Report a security issue

Send suspected vulnerabilities or unauthorized access reports to [email protected]. Include the affected page, what happened, and how we can reproduce it. Do not include passwords, verification codes, full bank account numbers, or sensitive receipt images.