Security & Privacy

Built for financial data. Serious about privacy.

Our platform has two products with different security models. The P&L Agent processes and discards. The Bookkeeping workspace stores transactions — and only transactions. Here's exactly what that means.

SOC 2 Type II Certified Infrastructure  ·  Zero PII stored — transactions only  ·  Bank statements deleted after extraction  ·  One-click client data deletion  ·  NDA-gated access

Security Principles

How we protect your financial data

SOC 2 Type II Certified Infrastructure

All AI processing runs through Anthropic's API, which is independently SOC 2 Type II certified — covering Security, Availability, and Confidentiality. Your financial data is processed through the same infrastructure Anthropic's enterprise customers use.

Never Used to Train AI Models

Anthropic's API explicitly excludes customer data from model training by default. The transaction data, revenue figures, and expense breakdowns you provide cannot be used to retrain or improve any AI model.

Bank Statements Deleted Immediately

Uploaded PDF and CSV bank statements are processed in memory and discarded the moment extraction is complete. The raw file is never written to disk or stored in any database. Only the extracted transaction records remain.

Transactions Only — No PII

The bookkeeping workspace stores transaction records (date, amount, category) to power the workspace. That's it. Account numbers, personal identifiers, and any other sensitive details are scrubbed before storage. No raw bank data persists.

NDA-Gated Access

Every bookkeeper and CPA who accesses client data must sign a Non-Disclosure Agreement before their account is activated. Access is reviewed and approved by an admin — no self-serve access to client workspaces.

Encrypted in Transit and at Rest

All data is encrypted in transit via TLS 1.2+ and at rest via AES-256. Every interaction between your browser and our servers uses HTTPS exclusively. Financial data is never transmitted in plain text.

Bookkeeping Workspace

Transactions only. Zero PII.

The workspace stores transaction records — date, amount, description, category — to generate P&Ls and sync with QuickBooks. No bank account numbers, no personal information, no raw statements. Everything else is discarded immediately.

One-click client deletion.Every client's transactions are scoped to that client alone. Delete a client and every transaction record, category, and audit log entry tied to them is permanently and immediately removed from our database.

What is stored

Transaction date

Date only — no timestamps or session metadata

Transaction amount

Numeric value only

Transaction description

Raw bank descriptor, used for vendor grouping

Category

Assigned by the bookkeeper or AI — stored for the P&L

Account type

Checking, savings, or credit card — used for reconciliation

What is never stored

  • Bank account or routing numbers
  • Raw PDF or CSV bank statement files
  • Customer names or customer-level transaction data
  • Employee names, salaries, or payroll details
  • Tax IDs, SSNs, or legal entity identifiers
  • Personal addresses, phone numbers, or email addresses
  • Data from other clients or other users

P&L Intelligence Agent

What the P&L Agent sends to AI

The P&L Agent passes your data to Anthropic's API for analysis. Only the figures needed for the report are transmitted — nothing else leaves your browser.

What is sent to the AI

Company name

Optional — can be omitted without affecting analysis quality

Industry label

e.g. "HVAC / Home Services" — used for benchmark comparison

Monthly revenue figures

Numeric totals only

Monthly expense figures

Numeric totals only

Budget figures

Numeric only, and only if present in your file

What is never sent

  • Employee names, salaries, or personal identifiers
  • Bank account or routing numbers
  • Customer names or customer-level data
  • Tax IDs or legal entity identifiers
  • Raw CSV files — only normalized numeric records are analyzed
  • Data from other users or other sessions

Data Lifecycle

What happens to your data over time

Bank statement uploadSeconds

Your PDF or CSV is read in memory, transactions are extracted, and the raw file is deleted immediately. Nothing is written to disk.

Transaction recordsUntil you delete them

Date, amount, description, and category are stored in your client workspace. You control this data — delete a client and all their records are permanently removed.

Anthropic API retentionUp to 30 days

Anthropic retains API prompts and responses for trust and safety monitoring — this applies to AI categorization and P&L analysis calls. Separate from the consumer Claude.ai product.

After 30 daysPermanently deleted by Anthropic

Anthropic permanently deletes all retained API data. No financial data persists beyond this window at the Anthropic layer.

Enterprise & Compliance

Strict requirements? We can work with them.

For firms in regulated industries or with formal security review requirements, we can configure Zero Data Retention on AI calls, strip optional identifiers, provide Anthropic's SOC 2 report, or discuss data handling requirements specific to your engagement.

Note: Our platform is not currently HIPAA compliant — Anthropic does not offer a Business Associate Agreement (BAA) at this time. It is also not suitable for EU data residency requirements without confirming region availability directly with Anthropic.