Encryption
Every document is encrypted with AES-256-GCM before storage and kept in private storage with no public URL. Provider API keys are encrypted the same way. All traffic uses TLS.
We handle your customers’ most sensitive financial documents. Here is exactly how we protect them.
Every document is encrypted with AES-256-GCM before storage and kept in private storage with no public URL. Provider API keys are encrypted the same way. All traffic uses TLS.
The database, files and processing servers are located in the Frankfurt region of the European Union.
Every request is checked against the user’s identity on the server. Users can access only their own checks; admin access to files is recorded in an audit log.
Passwords are stored only as scrypt hashes. Brute-force protection, temporary lockout, rate limiting and secure session cookies (HttpOnly, Secure, SameSite).
Original files are deleted automatically at the end of your plan’s retention period (7 to 90 days, or per agreement). You can delete a check manually at any time.
Visual analysis runs on Google Gemini API and, where configured, on a private open model. Document content is treated strictly as data and protected against hidden instructions.
Strict nonce-based Content-Security-Policy, HSTS, clickjacking protection, file type validation by content, size and rate limits, and parameterised database queries only.
Found a security issue? Write to our privacy and security address and we will respond within 72 hours.