Security
CashoutGuard protects money-moving decisions for rewards, GPT and offerwall businesses. This page explains how we protect your data and your users' data. It describes what is in place today, not plans.
Where your data lives
- Hosting: dedicated servers at Hetzner Online GmbH in Nuremberg, Germany (European Union).
- Traffic: every connection to the website, dashboard and API is encrypted with TLS (HTTPS only, HSTS enabled).
- Backups: the database is backed up every night and old backups are rotated automatically.
What we store, and how
We keep only what fraud prevention needs, and we minimise it where we can.
| Data | How it is stored |
|---|---|
| End-user email addresses | One-way SHA-256 hash of the address, plus the email domain |
| Payout addresses (PayPal, wallets…) | One-way SHA-256 hash, scoped to your site |
| Device characteristics | Raw signals needed for detection plus stable device hashes |
| IP addresses | Stored with the event, deleted with it at the end of your retention period |
| Your secret API keys | Only a SHA-256 hash is stored. The full key is shown once and cannot be recovered |
| Dashboard passwords | Hashed with bcrypt, never stored in plain text |
| Card details | Never touch our servers. Card payments are handled by Stripe |
Event history is deleted automatically after your plan's retention period (7 to 365 days). Cashout decisions you made are kept for your records.
Access and accounts
- Passwords must be at least 10 characters and are checked against known data breaches (k-anonymity, the password itself is never sent).
- Sign-in, password reset and API endpoints are rate limited.
- Accounts must confirm their email address before using the dashboard.
- Two-factor authentication with any authenticator app (Google Authenticator, 1Password, Authy), with one-time recovery codes. Each code works only once.
- Each API key belongs to one site. Public keys can only send signals from the domains you allow; secret keys stay on your server.
- Access by our team to customer accounts is logged in an audit trail.
Application security
- Security headers on every response: HSTS, no framing, no content sniffing, strict referrer policy and a restrictive permissions policy.
- Webhooks you receive from us are signed with HMAC-SHA256 so you can verify they came from CashoutGuard.
- Outgoing webhook calls are blocked from reaching private or internal networks.
- Payment notifications from Stripe and our crypto provider are verified by signature, then checked again against the provider before any plan changes.
- Errors and service health are monitored around the clock, with automatic alerts to our team.
Your users' privacy
The collector script uses a single random first-party identifier. It does no advertising or cross-site tracking and it never reads form fields, passwords or page content. Fraud prevention is a legitimate interest under the GDPR. Our Data Processing Agreement and Privacy Policy cover the details, including sub-processors.
Reporting a vulnerability
Found a security problem? Email security@cashoutguard.com with the steps to reproduce it. We reply within 2 business days, keep you updated while we fix it and credit you if you wish. Please do not access other customers' data, run denial-of-service tests or use automated scanners against production. Our machine-readable contact is at /.well-known/security.txt.
Questions about security or compliance: support@cashoutguard.com.