Security overview

Read-only by design.

DimeProof is designed to organize spending evidence without moving money or modifying mailboxes.

Bank access

Users connect through Plaid Link. DimeProof requests transaction access only, does not receive bank passwords, and cannot initiate payments.

Email access

Email integrations are read-only. DimeProof scans selected labels or folders for receipt evidence and does not send, delete, move, or modify messages.

Encrypted tokens

Provider OAuth tokens are encrypted server-side and are never returned to the browser.

Protected sessions

Sessions are random, hashed, expiring, and revocable. OAuth attempts are one-time, browser-bound, and protected with PKCE.

Minimized evidence

The current Gmail service does not download attachments or retain complete email bodies.

User control

Users can disconnect providers, delete imported evidence, or delete their DimeProof account.

Each mailbox provider is enabled only after its external approval and a real-account production smoke test pass.

Security reports may be sent to security@dimeproof.com.