Security & Privacy
Our platform has two products with different security models. The P&L Agent processes and discards. The Bookkeeping workspace stores transactions — and only transactions. Here's exactly what that means.
SOC 2 Type II Certified Infrastructure · Zero PII stored — transactions only · Bank statements deleted after extraction · One-click client data deletion · NDA-gated access
Security Principles
All AI processing runs through Anthropic's API, which is independently SOC 2 Type II certified — covering Security, Availability, and Confidentiality. Your financial data is processed through the same infrastructure Anthropic's enterprise customers use.
Anthropic's API explicitly excludes customer data from model training by default. The transaction data, revenue figures, and expense breakdowns you provide cannot be used to retrain or improve any AI model.
Uploaded PDF and CSV bank statements are processed in memory and discarded the moment extraction is complete. The raw file is never written to disk or stored in any database. Only the extracted transaction records remain.
The bookkeeping workspace stores transaction records (date, amount, category) to power the workspace. That's it. Account numbers, personal identifiers, and any other sensitive details are scrubbed before storage. No raw bank data persists.
Every bookkeeper and CPA who accesses client data must sign a Non-Disclosure Agreement before their account is activated. Access is reviewed and approved by an admin — no self-serve access to client workspaces.
All data is encrypted in transit via TLS 1.2+ and at rest via AES-256. Every interaction between your browser and our servers uses HTTPS exclusively. Financial data is never transmitted in plain text.
Bookkeeping Workspace
The workspace stores transaction records — date, amount, description, category — to generate P&Ls and sync with QuickBooks. No bank account numbers, no personal information, no raw statements. Everything else is discarded immediately.
One-click client deletion.Every client's transactions are scoped to that client alone. Delete a client and every transaction record, category, and audit log entry tied to them is permanently and immediately removed from our database.
Transaction date
Date only — no timestamps or session metadata
Transaction amount
Numeric value only
Transaction description
Raw bank descriptor, used for vendor grouping
Category
Assigned by the bookkeeper or AI — stored for the P&L
Account type
Checking, savings, or credit card — used for reconciliation
P&L Intelligence Agent
The P&L Agent passes your data to Anthropic's API for analysis. Only the figures needed for the report are transmitted — nothing else leaves your browser.
Company name
Optional — can be omitted without affecting analysis quality
Industry label
e.g. "HVAC / Home Services" — used for benchmark comparison
Monthly revenue figures
Numeric totals only
Monthly expense figures
Numeric totals only
Budget figures
Numeric only, and only if present in your file
Data Lifecycle
Your PDF or CSV is read in memory, transactions are extracted, and the raw file is deleted immediately. Nothing is written to disk.
Date, amount, description, and category are stored in your client workspace. You control this data — delete a client and all their records are permanently removed.
Anthropic retains API prompts and responses for trust and safety monitoring — this applies to AI categorization and P&L analysis calls. Separate from the consumer Claude.ai product.
Anthropic permanently deletes all retained API data. No financial data persists beyond this window at the Anthropic layer.
Enterprise & Compliance
For firms in regulated industries or with formal security review requirements, we can configure Zero Data Retention on AI calls, strip optional identifiers, provide Anthropic's SOC 2 report, or discuss data handling requirements specific to your engagement.
Note: Our platform is not currently HIPAA compliant — Anthropic does not offer a Business Associate Agreement (BAA) at this time. It is also not suitable for EU data residency requirements without confirming region availability directly with Anthropic.