Trust Center

StatementFlow handles financial documents on behalf of accountants, auditors and finance teams. This page describes the controls that are in place today. It is maintained by StatementFlow and is not an independent certification.

AES-256 encryption at rest

Every uploaded statement is encrypted at rest with AES-256 in isolated, access-controlled storage. Only your account can request the file.

TLS 1.3 in transit

All traffic between your browser and StatementFlow is encrypted with TLS 1.3. Legacy protocol versions are refused.

Automatic deletion

You choose the retention window at upload time — immediately, one hour, 24 hours or 30 days. Files and their extracted data are removed when the window closes.

No AI training

Your documents and extracted transactions are never used to train models, and are never shared with third parties for model development.

Privacy by design

Access is scoped per account at the database level. Staff do not browse customer documents, and every download or deletion is written to an audit log.

Minimal data collection

We store the statement file, the extracted transactions and the metadata needed to run your account. Nothing else is collected or profiled.

Shared responsibility

StatementFlow is responsible for securing the platform: encryption, access control, retention enforcement and audit logging.

Your organisation remains responsible for who you invite to your account, the documents you choose to upload and the retention policy you select.

Bank coverage

Statement layouts for most banks recognised automatically — no template setup required. Every statement is processed under the same encryption and retention controls.