Security
Last updated: September 2026. A bank statement is about as sensitive as a document gets, so this page says exactly what happens to yours, in the order it happens, and what does not happen. It does not carry compliance badges: stmtai is a small service and has not been through a SOC 2 or ISO 27001 audit. What it has is a design that keeps your file for the shortest possible time.
The short version
- Your statement goes from your browser to a locked storage box that only you and our reading step can open. If it has a password, it is removed on your computer first, and the password stays there.
- It is read once, by a program inside our own cloud account, and the rows come back as a table.
- The service attempts to delete the file immediately after reading it; a storage lifecycle rule is the fallback if that deletion fails.
- The table becomes eligible for deletion after 7 days (1 day without an account). Or press Delete now.
- The Excel, QuickBooks, Xero, Tally and CSV files are made on your own computer from that table. Nothing is sent anywhere when you press a download button.
- Nobody reads your statement, nothing is used to train anything, and there are no advertising or tracking scripts on any page.
Not ready to upload a real statement? Try the sample first; the whole flow works without sending anything. The rest of this page is the detailed version, for anyone who wants to check the claims.
Want to share less?
You can black out the account number, the address and the name on the statement before uploading, with the redaction tool in Preview (Mac), Adobe Reader or your bank app's share sheet. The balance check only needs the dates, descriptions, amounts and balances, so it works exactly the same. The account number is used for one thing: telling statements of different accounts apart when you upload several; without it, statements with the same bank name are treated as one account.
In transit
- Every page and every upload is served over HTTPS. Plain HTTP is redirected, and browsers are told to remember that for a year (HSTS with includeSubDomains).
- Your file goes from your browser straight to a private storage bucket in Amazon S3 using temporary AWS credentials scoped to your identity. It does not pass through a web server we run.
- The bucket refuses any connection that is not encrypted.
At rest
- The bucket is private. Nothing in it has a public URL, and objects are encrypted with S3 server-side encryption.
- Your upload lands under a prefix scoped to your own identity. Other users cannot list or read it; the processing function and the results page are the only readers.
- Extracted results are stored as JSON in the same bucket and in a DynamoDB table with an expiry: 7 days for signed-in users, 1 day for anonymous visitors. AWS lifecycle and table-expiry processes remove eligible data asynchronously, so physical deletion can occur after that eligibility date.
During processing
- A processing function inside our AWS account reads the file once and sends the pages to Amazon Bedrock to extract the transactions. Bedrock does not store or train on customer inputs.
- One model does the reading, with two others standing by in the same US regions. If the first is unavailable or throttled, the page is read by the next one and the balance check runs on the result as usual, so a supplier outage does not stop your conversion.
- The service attempts to delete the original file when processing finishes, whether the conversion succeeded or failed. A lifecycle rule removes any file left behind.
- Each conversion is locked so that a duplicate delivery from storage cannot run the job twice or charge pages twice.
- Logs record that a conversion happened, how many pages it had and any error message. Transaction rows, balances and descriptions are never written to logs.
Exports happen in your browser
The Excel, CSV, QuickBooks, Xero, Sage and Tally files are built in your browser from the table on screen. Nothing extra is uploaded when you click a download button, and edits you make to a row are saved back to your result only when you choose to save them.
Accounts and payments
- Sign-in is by email through Amazon Cognito. We store your email address, your plan and your page counts, and nothing else about you.
- Anonymous visitors are counted by a random Cognito identity; our usage record for it expires after 30 days.
- Payments are taken by Dodo Payments as merchant of record. Card numbers never reach our systems; we receive a customer identifier and the product bought, and webhook events are verified and recorded so a repeated event cannot credit pages twice.
- API keys are shown once when created, stored hashed, and can be revoked from the account page.
The application itself
- Response headers deny framing by other sites, block content-type sniffing, restrict the referrer, and turn off camera, microphone and geolocation for the page.
- Results pages are marked no-store and noindex so a browser or a search engine does not keep a copy.
- No advertising or analytics trackers, and no third-party scripts on the page. A Content-Security-Policy header enforces this: browsers refuse to run any script that is not ours, and the page may only talk to our own origin and the AWS services it uses. The only cookie is the one that keeps you signed in.
- The web framework is kept on a release with current security patches, and dependencies are reviewed when they change.
What you can do
- Press Delete now on any results page to remove a result before its expiry.
- Delete your account data from the bottom of your account page. Feedback or support correspondence is retained separately.
- If a PDF needs a password, the prompt you see is handled entirely on your computer: the file is unlocked in your browser and an unlocked copy is what gets uploaded. The password is never sent to us. If you would rather not type it at all, save an unlocked copy from your PDF viewer first and upload that.
- Black out the account number, name and address before uploading if you prefer; the balance check does not need them.
Reporting a problem
If you believe you have found a security issue, email support@stmtai.com with the details and we will reply within two business days. Please do not test against other people's data. For what we store and for how long, see the privacy page.