Security
Last updated: September 12, 2026
Bank statements are sensitive. This page describes the controls we actually use — not certifications we have not obtained.
Transport encryption
statementkit.com is served over HTTPS. Uploads and API calls use TLS. We do not offer an unencrypted upload path.
Accounts
You must sign in to upload statements. Passwords are stored as one-way hashes, not plain text. Sessions expire. Each user’s statements are scoped to that account in the application.
Uploads
We accept PDF statements. Password-protected or encrypted PDFs are rejected and not processed. Files are stored on our application server so we can extract transactions and so you can review or reprocess them. Delete a statement from your dashboard when you no longer need it.
Extraction
PDFs are sent to OpenAI’s API over HTTPS to extract transaction rows. We do not use your files to train our own models. See the Privacy Policy for what is shared with processors.
Payments
Subscriptions are charged by PayPal. We do not collect or store full payment-card numbers on StatementKit servers.
What we do not claim
We have not published a SOC 2 or ISO 27001 report for StatementKit. We do not claim that files exist only “in memory” or that they are wiped the instant extraction finishes. They remain in your account until you delete them.
Your responsibilities
- Use a unique password and keep it private
- Unlock password-protected PDFs on a machine you trust before uploading
- Review extracted data before importing it into accounting software
- Sign out on shared computers
Report a vulnerability
If you believe you found a security issue, email support@devloggic.com with details. Please do not publicly disclose it until we have had a reasonable chance to fix it.
Related: Privacy Policy · Terms of Service