Security at CashShield
Updated September 11, 2026
CashShield is operated by Xmbroider LLC.
Account protection
- Verified email is required before household financial data can be accessed.
- SMS multi-factor authentication is required for protected household functions.
- Phone changes require an authenticated session and access to an enrolled verification method.
- Automatic phone-replacement recovery is disabled because email access alone is not enough to replace a financial account’s second factor.
Data boundaries
- Firestore and Storage rules require verified authentication, completed MFA, and current household membership.
- Plaid access tokens, Stripe customer mappings, subscription status, recovery controls, and usage counters are kept in server-only collections.
- Household owners control invitations and subscription management. Household members can access shared household records.
- Service secrets are stored in Google Secret Manager and granted only to the functions that need them.
Provider verification
CashShield validates Plaid webhook signatures and request-body hashes before queuing synchronization. Stripe webhook signatures are checked against the original request body with a limited timestamp window. Subscription access is reconciled against Stripe’s current records; a browser return link cannot grant Premium access.
Payments and receipts
Stripe hosts payment entry and stores payment-card details. CashShield stores subscription identifiers and status rather than full card numbers. Receipt photos are available only to authenticated members of the household. Gemini processes submitted receipt images to return structured merchant, total, date, and item data.
What users can do
Use a unique password, protect your email and phone accounts, keep a backup verification phone, review household membership, disconnect old institutions, and never share verification codes. Review receipt extractions and forecasts before relying on them.
Report a security issue
Send suspected vulnerabilities or unauthorized access reports to [email protected]. Include the affected page, what happened, and how we can reproduce it. Do not include passwords, verification codes, full bank account numbers, or sensitive receipt images.