Security
Security
Current controls for uploaded statements, account access, saved work, and payment records.
Updated 16 Jul 2026
Statement Processing
- Uploaded statement PDFs are processed to create a preview and are not stored as original files after conversion.
- Digital, text-based PDFs are supported; scanned files are treated as limited input.
- File size, page count, processing time, and request-rate limits are enforced.
Accounts And Access
- Passwords are protected with salted scrypt hashes.
- Session and workspace cookies are HTTP-only, same-site, and secure in production.
- Saved conversions, projects, organizations, and payment records are checked against the active user and workspace role.
Stored Data
- Saved conversion records contain parsed data needed to reopen previews and regenerate exports.
- Payment proof files are content-validated, access-controlled, and removed after the configured retention period.
- Database connections use TLS certificate verification.
Report A Security Issue
Use the contact page to report a suspected security or privacy issue. Do not include bank statements, passwords, or payment proof files in the message.
