Rythm security and privacy
Rythm is non-custodial by design: we never hold your money, never store your email content, never keep Cashu tokens. Email scanning happens in-memory for milliseconds to verify a payment proof, then the content is discarded. OAuth refresh tokens are KMS-encrypted at rest. CASA Tier-2 security audit completed (39 of 39 test cases passed). The architecture is fail-open: if anything breaks on our end, email delivers normally.
Does Rythm read my emails?
Rythm scans incoming unknown-sender emails in-memory for milliseconds to check for a Cashu payment proof. Content is discarded immediately. We never store, share, or repurpose email content.
Is Rythm non-custodial?
Yes. Cashu tokens are validated in-memory and discarded. Payments flow from sender, to a public Cashu mint, to your Lightning wallet. Rythm is never in the middle.
Is Rythm SOC 2 certified?
Not yet. SOC 2 is planned after CASA Tier-2 finalizes. We do not claim certification we have not achieved.
Secure My Inbox