Encrypted · Purged after 24h · MFA ready

Bank-Grade Security.

We employ bank-grade protocols to ensure your financial statements are parsed, processed, and permanently purged with zero compromise.

Last updated: May 20, 2026

security_policy.tsx

1Security Overview

At FinzFlow, we recognize that bank statements contain highly sensitive financial information. Security is a core requirement in every feature we ship — not an afterthought.

Zero Storage Commitment: We do not build permanent transaction profiles or aggregate your banking records. FinzFlow is designed to be a temporary utility — we parse, convert, and delete.

2Data Encryption

Your files and data are protected by industry-standard encryption at all times:

In Transit — TLS 1.3

All traffic between your browser and our servers is encrypted using Transport Layer Security (TLS 1.3), preventing eavesdropping or tampering.

At Rest — AES-256

Uploaded statements are encrypted immediately upon arrival using 256-bit Advanced Encryption Standard (AES-256).

3Statement Deletion Protocol

We enforce automated purging to minimise risk from data retention:

Temporary Data Lifecycle
Immediate PurgeClick "Delete File" in your dashboard to destroy the PDF and spreadsheet instantly.
Auto 24-Hour PurgeAll converted files older than 24 hours are automatically destroyed by system cron jobs.
No Backup RetentionDeleted bank statements are not archived in database backups — they are gone for good.

4Hosting & Infrastructure

FinzFlow is hosted on leading, secure cloud platforms (primarily AWS and Vercel).

Certified Datacenters

Our servers run in physical environments certified for ISO 27001, SOC 2, and PCI-DSS compliance.

Active Firewalls (WAF)

Web Application Firewalls monitor and filter requests to guard against DDoS attacks, SQL injection, and web exploits.

5Account & Auth Security

Clerk Authentication

We use Clerk to handle authentication, session keys, and password guidelines — we never see or store your password in plain text. Multi-Factor Authentication (MFA) is supported and strongly encouraged for all accounts.

6Vulnerability Disclosure

If you believe you have discovered a security vulnerability in FinzFlow, please do not exploit it publicly. Contact us immediately so we can coordinate a fix responsibly.

Report a Vulnerability

security@puretextclean.com

We review reports within 48 hours and coordinate standard disclosure timelines.