Security FAQ

    Vendor security questionnaire

    Common security questions pre-answered for your firm's vendor review process. Download a summary to attach to your vendor file.

    Do you store uploaded documents?

    No. All processing occurs in volatile memory (RAM). Files are never written to disk, database, or any persistent storage system.

    What encryption do you use?

    TLS 1.3 for data in transit. There is no data at rest because nothing is stored.

    Do you use third-party sub-processors?

    Yes. DeepSeek (AI text structuring — receives only the statement text extracted from your PDF, never the file itself; refer to DeepSeek's privacy policy for their data handling). Supabase (authentication and billing metadata only — no document content touches Supabase).

    Do you have SOC 2 certification?

    Not yet. We are on a SOC 2 Type II roadmap. Our zero-retention architecture eliminates the primary risk SOC 2 addresses — stored data breach — because no customer data exists to steal.

    Where are your servers located?

    Supabase Edge Functions run on AWS infrastructure. AI text structuring is processed by DeepSeek's API (see their documentation for processing locations). All data transit occurs within encrypted channels.

    Do you use advertising trackers?

    No. We use Google Ads conversion tracking only (page-level, no user-level tracking). No Google Analytics, no Facebook Pixel, no remarketing cookies, no fingerprinting.

    What is your data retention period?

    Zero. Documents exist only during the active conversion session (typically 5–30 seconds). After the converted file is delivered to the user's browser, all memory is deallocated.

    Do you train AI models on uploaded data?

    We never train models on your data, and we never store it — your file exists only in memory during conversion. AI text structuring is handled by DeepSeek's API; their data handling is governed by their own privacy policy, and we send them only the extracted statement text, never your PDF or your identity.

    What happens if there's a breach?

    Our zero-retention architecture means a breach of our systems would expose no customer financial data, because none exists to steal. Account credentials (email + hashed password) are the only user data stored, protected by Supabase's SOC 2 compliant infrastructure.

    Can you sign a BAA or DPA?

    Contact us at [email protected] to discuss Business Associate Agreements, Data Processing Agreements, or other vendor security documentation.

    Need additional security documentation or want to discuss a BAA/DPA?

    [email protected]