Security overview
Read-only by design.
DimeProof is designed to organize spending evidence without moving money or modifying mailboxes.
Bank access
Users connect through Plaid Link. DimeProof requests transaction access only, does not receive bank passwords, and cannot initiate payments.
Email access
Email integrations are read-only. DimeProof scans selected labels or folders for receipt evidence and does not send, delete, move, or modify messages.
Encrypted tokens
Provider OAuth tokens are encrypted server-side and are never returned to the browser.
Protected sessions
Sessions are random, hashed, expiring, and revocable. OAuth attempts are one-time, browser-bound, and protected with PKCE.
Minimized evidence
The current Gmail service does not download attachments or retain complete email bodies.
User control
Users can disconnect providers, delete imported evidence, or delete their DimeProof account.
Security reports may be sent to security@dimeproof.com.