ExpressHold Security & Data

This page describes how ExpressHold handles data, how it is secured, and how Regulation CC dollar thresholds are kept current. It is intended to support subscriber institutions in vendor due diligence, data privacy assessments, and regulatory compliance reviews.

Version 1.2  ·  Effective August 1, 2026  ·  Applies to ExpressHold application version 1.2

Data Handling

Statement of Client-Side Processing

ExpressHold is a browser-based application. All calculation logic, scenario evaluation, date computation, and notice generation are performed entirely within the user's web browser using client-side JavaScript. The application does not transmit any user-entered data to any server operated by CU Risk Advisors or any third party.

How it works

  1. The subscriber institution accesses the Hosted Version through a password-protected URL on a Squarespace web platform.
  2. The HTML, CSS, and JavaScript code is delivered to the user's browser as a static page load.
  3. All user input — deposit dates, amounts, item types, hold conditions — is entered and processed in the browser.
  4. All calculation results, availability dates, hold reasons, audit codes, and printed notices are generated in the browser. Printed notices render through a hidden same-origin frame; no notice content leaves the browser.
  5. No input, result, or notice content is transmitted to or stored on any CU Risk Advisors server.
  6. The application makes no outbound network requests during or after a hold calculation.

Data retention

CU Risk Advisors does not collect, receive, transmit, store, log, or retain any data entered into ExpressHold — including deposit dates, amounts, or types; account identifiers or transaction references; hold calculation inputs or results; printed notice content; or audit codes.

Session data exists only in the browser's memory for the duration of the active session. ExpressHold does not use browser local storage, session storage, or cookies to persist any entered data. All session data clears when the tab or browser closes, or the page reloads.

A note on cookies: the statement above concerns the ExpressHold application itself. Separately, the Squarespace platform may set its own cookies on the hosted page in the ordinary course of serving the site, as described in the CU Risk Advisors Privacy Policy. Those are platform cookies, contain no data entered into ExpressHold, and are not used by the application.

Personally identifiable information

ExpressHold does not collect or display member/customer names or account numbers. A Transaction Reference field accepts a non-PII reference such as a teller batch number; users are instructed at the point of entry not to input PII there. CU Risk Advisors is not responsible for data entered in contravention of that instruction.

Local License and demonstration copies

The Local License Version and demonstration copies use the identical client-side architecture described above. When opened from a local workstation or internal network, no network requests of any kind are made — the application executes entirely from the local file. References to Squarespace hosting apply only to the Hosted Version. Demonstration copies additionally embed an expiration date, checked locally with no data transmission, after which the application disables itself.

Security

Encryption and Security Statement

Transport layer security

All access to the Hosted Version is delivered exclusively over HTTPS. Squarespace enforces HTTPS for all page loads and redirects any HTTP request automatically. HTTP access is not permitted.

ProtocolHTTPS enforced; HTTP redirected automatically
TLS versionTLS 1.2 minimum; TLS 1.3 supported
Certificate authorityManaged by Squarespace (Let's Encrypt / DigiCert)
Certificate renewalAutomatic via Squarespace platform
HSTSEnabled by Squarespace
Mixed contentNone — all resources served over HTTPS

Password protection

Each subscriber's hosted installation is protected by a page-level password managed through Squarespace. Passwords are set by CU Risk Advisors at installation, communicated to the subscriber's designated contact by secure means, not stored by CU Risk Advisors after delivery, and changeable on request. Subscribers are responsible for password confidentiality and for revoking access for departed staff by requesting a change.

Data in transit and at rest

Because ExpressHold is client-side, no operational data is transmitted from the browser to any server. The only data transmitted is the initial page load request, encrypted via TLS. No database, file storage, or logging system under CU Risk Advisors' control retains any data entered into ExpressHold.

The Hosted Version runs on Squarespace, a SOC 2 Type II certified platform. CU Risk Advisors is a small independent operator and does not independently hold SOC 2, ISO 27001, or similar certifications — hosting infrastructure security is provided and certified at the Squarespace platform level. Review Squarespace's security documentation at squarespace.com/security.

Local License and demonstration copies

These are delivered as single, self-contained HTML files in protected (obfuscated) form. Opened from a local workstation or internal network, the application makes no network requests — TLS considerations above apply only to the Hosted Version. Obfuscation protects against casual inspection and tampering; it does not affect data handling, and obfuscated builds transmit no data.

Vulnerability and incident response

If CU Risk Advisors becomes aware of a security vulnerability or an incident affecting subscriber access, we will:

  1. Notify affected subscribers by email within 24 hours of confirmed discovery.
  2. Disable affected access as appropriate until remediated.
  3. Provide a written summary of the incident, affected systems, and remediation steps within 5 business days.

These commitments cover the ExpressHold application and access CU Risk Advisors administers — not incidents originating within a subscriber's own network or on the Squarespace platform. To report a security issue: info@mycurisk.com.

Regulatory Maintenance

Regulation CC Threshold Maintenance Statement

Regulation CC (12 C.F.R. Part 229) sets two dollar thresholds subject to periodic Federal Reserve adjustment:

Threshold Current amount Citation
Minimum next-day availability$275.00§229.10(c)(1)(vii)
Large deposit exception$6,725.00§229.13(b)

Most recent adjustment effective July 1, 2025.

Within 72 hours of the effective date of any Federal Reserve adjustment, CU Risk Advisors updates the ExpressHold application code for all active subscriber pages to reflect the new amounts.

This applies to the minimum next-day availability amount, the large deposit exception threshold, and any other dollar threshold in ExpressHold's scenario logic. Where the Fed announces an adjustment fewer than 30 days before its effective date, the 72-hour period runs from CU Risk Advisors' receipt of notice instead. This commitment covers the Hosted Version; Local License files are updated on request per the Software Products Supplement, with the standard update fee applying per delivery.

As of application version 1.2, thresholds are embedded in provider-maintained code and are not editable by subscriber staff — eliminating the risk of inadvertent local modification.

Notification & verification

Upon completing an update, CU Risk Advisors emails each subscriber's designated contact confirming the update, its date, and the new amounts, and retains a record of the notification. Current thresholds always display on the application's Hold Matrix tab. Subscribers are encouraged to independently monitor Federal Reserve announcements and to contact us immediately at any discrepancy.

Limitation

This maintenance commitment applies only to active subscribers with a current paid subscription. Subscriptions that have lapsed will not receive threshold updates until renewed; CU Risk Advisors is not liable for compliance failures arising from use after a lapse. Demonstration copies self-disable at their embedded expiration date, preventing continued use of a copy that may hold outdated thresholds.

The statements on this page are incorporated into the CU Risk Advisors Software Products Supplement and form part of the agreement with subscribing institutions. Prior versions available on request at info@mycurisk.com.