· Security Sign in ← Home

Security & API Key Storage

Last updated: 2026-05-05

You bring your own keys. We are the runtime that uses them on your behalf — nothing more. Below is exactly what happens to a key the moment you paste it in.

1. What you control

Every paid integration in CASH.BOT is BYOK: you bring your own Anthropic, OpenAI, Google, ElevenLabs, Stripe, Twilio, Vultr, Railway, Resend, etc. key. You can:

2. How a key is stored

3. How a key is used

4. What we will NEVER do

What we DO

  • Store keys encrypted at rest.
  • Strip keys from log lines.
  • Show you every key we hold.
  • Let you rotate or delete on demand.
  • Honor spend ceilings you set.

What we DO NOT

  • Log, echo, or print plaintext keys.
  • Share your key with another user.
  • Train on your prompts or outputs.
  • Retain decrypted keys in memory after a request.
  • Auto-rotate or auto-charge against your provider account.

5. Authentication & sessions

6. Transport & infrastructure

7. Disclosure & reporting

If you discover a vulnerability, please email security@cash.bot. We will acknowledge within 48 hours and aim to remediate within 7 days for high-severity reports. We do not currently run a paid bug bounty, but we credit responsible disclosures publicly with permission.

If we learn of a breach affecting your data, we will notify the affected accounts within 72 hours of confirmation, including what was accessed and what we are doing about it.

8. AI provider compliance

Questions?
Security disclosures: security@cash.bot
Account / billing: billing@cash.bot
Live support: cash.bot/support
Related: Privacy Policy · Terms of Service · Refund Policy