HomeHelp

Security at ZeroParse Statements

For anyone assessing us as a vendor. We built the product so that we never hold a bank statement we can read, which makes most of the usual questions short.

Last reviewed 4 October 2026.

How statements are handled

CSV, Excel, OFX and QFX files
Read entirely in your browser. They are never sent to our servers.
PDFs
Sent over TLS to our extraction service, held in memory only while they are read, and dropped as soon as the transactions are returned, whether extraction succeeds or fails. They are never written to disk. Our backend tests, run on every change, check that both typed and scanned PDFs leave nothing on disk.
Statements clients send through upload links (Firm)
Encrypted in the client's browser with a key only the firm holds, behind a passphrase we never receive. We store them in that form until the firm collects them, or 72 hours at most, then delete them. We hold no key that can open them.
What we do keep
Your account (email, plan, credit balance and credit history), and for each run a non-content record: file type, page count and timing. Never transaction data.
Statements in error reports or logs
No. Error reports are scrubbed before they leave: no request bodies, cookies, headers or query strings, and accounts appear only as an internal ID or one-way hash.

Who processes what

The services that handle data for us. The legal version, with each one's limits, is Annex III of our Data Processing Agreement.

ProviderWhat it doesSees statement contentsWhere
RenderRuns PDF extractionIn memory, brieflyUnited States (Virginia)
VercelHosts the website and its server functionsNeverUnited States (Washington, D.C.)
SupabaseSign-in and the account databaseNeverClient uploads: encrypted, unreadable, 72 hours at mostUnited States (N. Virginia)
StripeTakes payment for your subscriptionNeverSet by Stripe
ResendSends account and support emailOnly if you attach oneSet by Resend
SentryError reports, with contents scrubbedNeverUnited States
CloudflareBot check (Turnstile) on sign-in and sign-up formsNeverSet by Cloudflare

We tell registered business accounts by email at least 14 days before adding or replacing a subprocessor with access to customer data.

Application and infrastructure

Encryption in transit
TLS 1.2 or higher everywhere, with HSTS (two years, subdomains, preloaded).
Encryption at rest
Account and billing data is held in Supabase's managed Postgres, encrypted at rest by the provider.
Tenant isolation
Postgres row-level security on every table in the database: one account's data can't be read by another signed-in user. The service credential that bypasses it is used only on our servers, never in the browser.
Browser protections
A Content Security Policy with per-request nonces, framing denied, MIME sniffing off, a strict referrer policy, and camera, microphone and location access turned off.
Sign-in
Email and password, or Google. Passwords must meet a length and complexity rule, sign-in attempts are rate-limited, and a Cloudflare Turnstile bot check guards sign-in, sign-up and password reset. Passwords are stored and checked by Supabase Auth; we never store one ourselves.
Our own access
The operations console is limited to a named allow-list of staff, each with a verified account. Every action taken on a customer's account there (support access, credit changes, refunds) is written to an append-only audit log.
Payments
Handled by Stripe. Card details go to Stripe directly and never reach our servers.

Your data

Export
Download everything we hold about your account, as JSON, from Account → Your data.
Deletion
Delete your account yourself from the same page. Statement contents need no deletion: we never had them.
Data processing agreement
Our DPA is part of our Terms for any account used to process clients' data, so it applies without a separate signature. Privacy is governed by our Privacy Policy under Singapore's PDPA.

Assurance, honestly

SOC 2 or ISO 27001
Not yet. We rely on our infrastructure providers' own certifications, and on request (once a year, or after a suspected incident) we'll complete your security questionnaire.
Multi-factor authentication
Not offered yet.
Breach notification
If we confirm a breach affecting your account credentials or billing data, we notify you without undue delay, under the PDPA. Statement contents can't be taken from us at rest, because we don't keep them.
Reporting a vulnerability
Email support@getzeroparse.com. Our security.txt says the same.
Company
Wedgr Technologies, Singapore (UEN 53532707B).