Security at SheetStatement
Bank statements are among the most sensitive documents you own. Here is exactly how we handle them.
Encrypted in transit
All traffic uses HTTPS (TLS 1.2+). Database connections are encrypted.
Minimal retention
The original file is processed in memory and not stored; only the extracted transactions you see in your dashboard are saved.
No training on your data
Statements are sent to our AI provider under API terms that exclude using customer data to train models.
Delete anytime
Remove any statement from your history with one click; it's permanently deleted from our database.
Account protection
Sign in with Google or with a password stored as a salted bcrypt hash. Sessions use signed, HTTP-only cookies.
Least privilege
Production secrets live in environment variables, never in source control, and only the application can access the database.
Found a vulnerability? Email [email protected].