Security at ZeroParse Statements
For anyone assessing us as a vendor. We built the product so that we never hold a bank statement we can read, which makes most of the usual questions short.
Last reviewed 4 October 2026.
Statements aren't stored
CSV and Excel files never leave your browser. PDFs are read in memory and dropped.
No AI
Extraction is rule-based. Nothing you upload trains any model, ours or anyone's.
Encrypted in transit
TLS 1.2 or higher, with HSTS preloaded for the whole domain.
We never see card numbers
Payments are taken by Stripe, on Stripe's own pages.
How statements are handled
- CSV, Excel, OFX and QFX files
- Read entirely in your browser. They are never sent to our servers.
- PDFs
- Sent over TLS to our extraction service, held in memory only while they are read, and dropped as soon as the transactions are returned, whether extraction succeeds or fails. They are never written to disk. Our backend tests, run on every change, check that both typed and scanned PDFs leave nothing on disk.
- Statements clients send through upload links (Firm)
- Encrypted in the client's browser with a key only the firm holds, behind a passphrase we never receive. We store them in that form until the firm collects them, or 72 hours at most, then delete them. We hold no key that can open them.
- What we do keep
- Your account (email, plan, credit balance and credit history), and for each run a non-content record: file type, page count and timing. Never transaction data.
- Statements in error reports or logs
- No. Error reports are scrubbed before they leave: no request bodies, cookies, headers or query strings, and accounts appear only as an internal ID or one-way hash.
Who processes what
The services that handle data for us. The legal version, with each one's limits, is Annex III of our Data Processing Agreement.
| Provider | What it does | Sees statement contents | Where |
|---|---|---|---|
| Render | Runs PDF extraction | In memory, briefly | United States (Virginia) |
| Vercel | Hosts the website and its server functions | Never | United States (Washington, D.C.) |
| Supabase | Sign-in and the account database | NeverClient uploads: encrypted, unreadable, 72 hours at most | United States (N. Virginia) |
| Stripe | Takes payment for your subscription | Never | Set by Stripe |
| Resend | Sends account and support email | Only if you attach one | Set by Resend |
| Sentry | Error reports, with contents scrubbed | Never | United States |
| Cloudflare | Bot check (Turnstile) on sign-in and sign-up forms | Never | Set by Cloudflare |
We tell registered business accounts by email at least 14 days before adding or replacing a subprocessor with access to customer data.
Application and infrastructure
- Encryption in transit
- TLS 1.2 or higher everywhere, with HSTS (two years, subdomains, preloaded).
- Encryption at rest
- Account and billing data is held in Supabase's managed Postgres, encrypted at rest by the provider.
- Tenant isolation
- Postgres row-level security on every table in the database: one account's data can't be read by another signed-in user. The service credential that bypasses it is used only on our servers, never in the browser.
- Browser protections
- A Content Security Policy with per-request nonces, framing denied, MIME sniffing off, a strict referrer policy, and camera, microphone and location access turned off.
- Sign-in
- Email and password, or Google. Passwords must meet a length and complexity rule, sign-in attempts are rate-limited, and a Cloudflare Turnstile bot check guards sign-in, sign-up and password reset. Passwords are stored and checked by Supabase Auth; we never store one ourselves.
- Our own access
- The operations console is limited to a named allow-list of staff, each with a verified account. Every action taken on a customer's account there (support access, credit changes, refunds) is written to an append-only audit log.
- Payments
- Handled by Stripe. Card details go to Stripe directly and never reach our servers.
Your data
- Export
- Download everything we hold about your account, as JSON, from Account → Your data.
- Deletion
- Delete your account yourself from the same page. Statement contents need no deletion: we never had them.
- Data processing agreement
- Our DPA is part of our Terms for any account used to process clients' data, so it applies without a separate signature. Privacy is governed by our Privacy Policy under Singapore's PDPA.
Assurance, honestly
- SOC 2 or ISO 27001
- Not yet. We rely on our infrastructure providers' own certifications, and on request (once a year, or after a suspected incident) we'll complete your security questionnaire.
- Multi-factor authentication
- Not offered yet.
- Breach notification
- If we confirm a breach affecting your account credentials or billing data, we notify you without undue delay, under the PDPA. Statement contents can't be taken from us at rest, because we don't keep them.
- Reporting a vulnerability
- Email support@getzeroparse.com. Our security.txt says the same.
- Company
- Wedgr Technologies, Singapore (UEN 53532707B).