ExpressHold Security & Data

How ExpressHold handles deposit information, what it stores and where, what CU Risk Advisors receives, and who is responsible for keeping the Regulation CC dollar thresholds current. Written to answer a vendor due diligence, data privacy, or third party risk review.

Applies to ExpressHold 3.0  ·  Last reviewed September 14, 2026

ExpressHold runs entirely inside the browser on the computer that opens it. It makes no network requests of any kind. There is no server, no account, no login, no telemetry, no analytics, no update check, and no external font or script. Nothing about a deposit, a member, or your institution ever reaches CU Risk Advisors, because there is nothing for it to reach.

This page summarises that for a third party risk file. The authoritative statements are the NOTICE file and section 9 of the User and Compliance Guide, both of which ship inside the download and are versioned with the software you actually have.

How deposit information is handled

All calculation, scenario evaluation, date computation, and notice generation happen in the browser. Deposit dates, amounts, hold amounts, item types, exception conditions, results, and notice content exist only in the page's working memory while you are using it. They are gone when the tab is closed or the page is reloaded, and the New calculation button clears them immediately.

ExpressHold does not ask for and does not display member or customer names or account numbers. The transaction reference field is free text intended for a teller number or a ticket number, and the field's own hint says not to enter names or account numbers in it.

What is written to the browser

DataWhere it goes
Deposit and hold entries, results, notice contentNowhere. Working memory only, cleared on reload, on tab close, and on New calculation.
Your configuration
institution name, telephone number, dollar thresholds, hold periods, notice labels, passphrase hash
The browser's local storage, on that workstation, in that browser profile. This is how the application stays configured between sessions. It holds no member or transaction data.
Anything at all, in the online sampleNowhere. The sample build has the storage code removed at build time rather than switched off. It cannot save.

Earlier CU Risk Advisors statements said ExpressHold does not use local storage. For deposit and transaction data that is correct and always has been. For configuration it was not, and the current documentation states the distinction precisely rather than overstating it.

What CU Risk Advisors receives

Nothing. No member or customer names, account numbers, deposit amounts or dates, transaction references, hold calculation inputs or results, printed notice content, or audit codes. Not in aggregate, not anonymised, not in error logs.

There is no party to collect it and no mechanism to collect it with. The software has no server to transmit to. A reviewer can confirm this in a few minutes by opening the file in a text editor and searching for fetch, XMLHttpRequest, WebSocket, and src=, or by loading it with the browser's network tab open and watching nothing happen.

Verifying this rather than taking our word for it

ExpressHold is licensed under the Apache License 2.0 and the complete source is published. For a product with no vendor, the ability to check is the due diligence answer. It is not a certification, and it is not offered as one.

  • Read the application. It is one HTML file. The calculation engine is separate from the interface, and every rule carries the provision of 12 CFR Part 229 it comes from.
  • Run the tests. The source package includes an offline regulatory test suite that runs with one command and names the provision each assertion pins, plus a second suite that drives the built application in a browser.
  • Rebuild it. Running the build script reproduces the distributed application byte for byte apart from the build date in its header comment, so you can confirm the file you were given matches the source you read.
  • Check the file inventory. Both packages carry SHA-256 checksums for every file.

The online sample, and where files are served from

The downloadable application is a local file. Once you have it, nothing about running it involves CU Risk Advisors or any website.

The online sample and the download links are served from this site, which is hosted by Squarespace over HTTPS. Squarespace keeps standard web server logs, including IP addresses, for visitors to any page here. That is ordinary website hosting and it is described in the Privacy Policy. It has nothing to do with the calculator itself, which transmits nothing whether you reach it from this site or from a copy on your own network.

About the online sample

The sample is a public page shared with everyone who visits. It stores nothing and sends nothing, but it is not private in the sense of being yours alone. Please do not enter real member names, account numbers, or other identifying information into it. Notices generated there are for demonstration and are not valid for member use.

Regulation CC thresholds are the operating institution's responsibility

Nobody is monitoring this for you

There is no subscription, no subscriber list, no update service, and no notification. CU Risk Advisors makes no commitment to update the Regulation CC dollar thresholds, to tell anyone when they change, or to maintain the software at all.

The amounts distributed with version 3.0 took effect July 1, 2025. The next adjustment is scheduled for July 1, 2030 and is normally announced well in advance. Keeping the figures current in your own installation is the responsibility of whoever operates it.

Section 10 of the User and Compliance Guide sets out what to do about that: assign it to someone by name, diary it, and update the Configuration tab when the amounts change. Changing the tool does not change your funds availability disclosure, your policy, or your staff training materials.

For your vendor management file

Downloading ExpressHold does not create a vendor relationship. There is no service, no hosting, no contract, no recurring payment, no access to your systems, and no data flow to a third party. There is nothing to assess, and no due diligence questionnaire that a meaningful answer could be given to.

CU Risk Advisors does not hold SOC 2, ISO 27001, or any other certification, and does not claim to. What is offered instead is the source code, the test suites with their regulatory citations, the change log, and file checksums, so that a reviewer can reach their own conclusion rather than relying on ours.

Your institution remains solely responsible for its funds availability policy, for the accuracy of the configuration it enters, for keeping the Regulation CC thresholds current, and for every notice it delivers to a member or customer. The software helps apply a regulation. It does not interpret that regulation for you and it is not a substitute for your own compliance review.

Support, defects, and vulnerabilities

The software is provided as-is with no support, no maintenance, and no monitoring. Nobody is obliged to answer a question, fix a defect, publish an update, or tell you when anything changes. Plan on that basis. That is stated in the NOTICE file and in the licence, and it is not softened here.

Defect reports and security findings are welcome at info@mycurisk.com and will be read. No response time is promised, no fix is promised, and no notification of other users is promised, because there is no list of users to notify. Sending or receiving a message does not create a support, consulting, or advisory relationship.

Because the source is published under a licence that permits modification, an institution that needs a defect fixed on a schedule is free to fix it, or to engage anyone it likes to fix it, without asking.

This page is a summary written for third party risk reviewers. It creates no obligation and makes no commitment. Where it differs from the NOTICE file or the User and Compliance Guide included in the version you downloaded, those documents govern, because they are versioned with the software and this page is not.

Last reviewed September 14, 2026  ·  Applies to ExpressHold 3.0  ·  ExpressHold  ·  Privacy Policy  ·  Apache License 2.0