Security
When you process client bank statements, you need to know exactly how that data is stored, who can access it, and when it is deleted. Here is the full picture.
All data transferred between your browser and our servers is encrypted using TLS 1.2 or higher. No unencrypted connections are accepted.
Uploaded files and extracted transaction data are stored using AES-256 encryption at rest, with files held in Amazon S3. Your documents are never stored in plain text.
Uploaded PDFs are kept until you delete them. Removing a statement from your dashboard takes one click, so nothing disappears while you still need it.
Every API request is checked against the account it belongs to, so users can only read and write their own data. Statements and transactions are invisible to other accounts.
We do not sell, rent, or share your financial data or extracted transactions with any third party for advertising, analytics, or any other purpose.
Document previews use signed, time-limited URLs that expire after one hour. Even if a URL is shared, it cannot be used after expiry.
We retain different types of data for different periods. The table below is the complete picture — no hidden retention.
You can delete a statement at any time from your dashboard. Until you do, your files stay available so you can come back to a conversion later.
The following third-party services process data on our behalf. Each is contractually obligated to protect your data and may only use it to deliver their service to us.
Documentric is not currently SOC 2 certified. Our infrastructure runs on Amazon Web Services and Vercel. We follow security best practices including encryption at rest and in transit, account-scoped access control, and signed, time-limited document URLs. Enterprise customers can request our security documentation.
We support the rights GDPR gives you over your data. Uploaded files are kept until you delete them, and you can delete a statement from your dashboard at any time. You can also request deletion of your account and all associated data by writing to privacy@documentric.com. See our Privacy Policy at /privacy for full details.
Yes. Files are kept until you delete them, and you can remove any statement from your dashboard at any time. There is no timer that clears your work while you still need it. To have your account and everything associated with it removed, write to privacy@documentric.com.
We share data only with the sub-processors listed on this page (Amazon Web Services, Vercel), and only to the extent necessary to deliver the service. We never sell data, share it with advertisers, or use it for any purpose beyond operating Documentric.
All data in transit is encrypted with TLS 1.2 or higher. Data at rest (files and database rows) is encrypted using AES-256, and uploaded files are stored in Amazon S3. Document preview URLs are signed and expire after one hour.
For the full legal picture, read our Privacy Policy. Privacy or data requests can be sent to privacy@documentric.com.