Trust information
Security
Security boundaries and responsible disclosure information for BankStatements.us.
We describe the access, storage, and lifecycle boundaries we can support without claiming certifications, audits, or guarantees.
Security boundaries
Individual accounts are separated by authenticated access boundaries. Document processing and private storage follow bounded lifecycle controls, including cleanup after completed, failed, or cancelled processing. This page does not claim certification, regulatory compliance, independent audits, penetration testing, encryption guarantees, or breach guarantees.
Report a security concern
Report a potential vulnerability to security@bankstatements.us. We target acknowledgment within 3 United States business days and an initial assessment within 10 United States business days. We will provide reasonable updates, but do not guarantee a universal remediation deadline.
Responsible disclosure
We welcome good-faith research that avoids customer data, privacy violations, disruption, denial of service, social engineering, physical attack, credential theft, destructive testing, and premature disclosure. Collect only the minimum proof needed and keep findings confidential until remediation or an agreed disclosure date. This safe harbor does not authorize activity outside these boundaries.