Trust Center
StatementFlow handles financial documents on behalf of accountants, auditors and finance teams. This page describes the controls that are in place today. It is maintained by StatementFlow and is not an independent certification.
Every uploaded statement is encrypted at rest with AES-256 in isolated, access-controlled storage. Only your account can request the file.
All traffic between your browser and StatementFlow is encrypted with TLS 1.3. Legacy protocol versions are refused.
You choose the retention window at upload time — immediately, one hour, 24 hours or 30 days. Files and their extracted data are removed when the window closes.
Your documents and extracted transactions are never used to train models, and are never shared with third parties for model development.
Access is scoped per account at the database level. Staff do not browse customer documents, and every download or deletion is written to an audit log.
We store the statement file, the extracted transactions and the metadata needed to run your account. Nothing else is collected or profiled.
StatementFlow is responsible for securing the platform: encryption, access control, retention enforcement and audit logging.
Your organisation remains responsible for who you invite to your account, the documents you choose to upload and the retention policy you select.
Bank coverage
Statement layouts for most banks recognised automatically — no template setup required. Every statement is processed under the same encryption and retention controls.