Trust information
Trust Center
Clear information about how BankStatements.us approaches financial documents, data handling, security, and the policies that govern the service.
Current availability
The public site and account experience are available. Public conversion and checkout are not currently available.
Privacy, security, lifecycle, and terms
Read the policies that explain our launch commitments and current public boundaries.
United States data residency
Customer data is stored and processed in the United States. We configure providers that handle account data, documents, extracted results, and service records for United States processing regions. The service is built for United States customers and does not offer an international processing region.
A data processing addendum is available by request at privacy@bankstatements.us.
Service providers and subprocessors
These active providers support the site, account experience, conversion, storage, infrastructure, billing, and related service operations. All customer-data processing is configured for the United States.
| Provider | Purpose | Data | Status | Region |
|---|---|---|---|---|
| Microsoft Azure | Document understanding and semantic mapping | Native document evidence | Active | United States |
| DigitalOcean | United States application infrastructure | Application and operational data | Active | United States |
| Render | Public website and application hosting | Account and application traffic | Active | United States |
| Cloudflare | DNS, traffic protection, and delivery | Network and security metadata | Active | United States |
| Neon | United States PostgreSQL database | Account and service records | Active | United States |
| Tigris | Private United States object storage | Uploaded documents and generated results | Active | United States |
| Stripe | Subscription billing and payment processing | Billing and transaction records | Active | United States |
| Resend | Transactional account email | Email address and message delivery metadata | Active | United States |
| GitHub | Source control and continuous integration | Source code and build metadata; no customer documents | Active | United States |
| PostHog | Basic product analytics | Privacy-minimized product events only | Active | United States |
This roster was last updated August 6, 2026. We will publish changes here before a new provider begins handling customer data when practical.
Responsible disclosure
Good-faith researchers can report a concern at security@bankstatements.us. Please avoid customer data, disruption, destructive testing, credential theft, and premature disclosure. Our Security policy explains the reporting boundary and response targets.