1Security Overview
At FinzFlow, we recognize that bank statements contain highly sensitive financial information. Security is a core requirement in every feature we ship — not an afterthought.
Zero Storage Commitment: We do not build permanent transaction profiles or aggregate your banking records. FinzFlow is designed to be a temporary utility — we parse, convert, and delete.
2Data Encryption
Your files and data are protected by industry-standard encryption at all times:
In Transit — TLS 1.3
All traffic between your browser and our servers is encrypted using Transport Layer Security (TLS 1.3), preventing eavesdropping or tampering.
At Rest — AES-256
Uploaded statements are encrypted immediately upon arrival using 256-bit Advanced Encryption Standard (AES-256).
3Statement Deletion Protocol
We enforce automated purging to minimise risk from data retention:
4Hosting & Infrastructure
FinzFlow is hosted on leading, secure cloud platforms (primarily AWS and Vercel).
Certified Datacenters
Our servers run in physical environments certified for ISO 27001, SOC 2, and PCI-DSS compliance.
Active Firewalls (WAF)
Web Application Firewalls monitor and filter requests to guard against DDoS attacks, SQL injection, and web exploits.
5Account & Auth Security
Clerk Authentication
We use Clerk to handle authentication, session keys, and password guidelines — we never see or store your password in plain text. Multi-Factor Authentication (MFA) is supported and strongly encouraged for all accounts.
6Vulnerability Disclosure
If you believe you have discovered a security vulnerability in FinzFlow, please do not exploit it publicly. Contact us immediately so we can coordinate a fix responsibly.
Report a Vulnerability
security@puretextclean.comWe review reports within 48 hours and coordinate standard disclosure timelines.