Security you can trust

Your financial data deserves serious protection. Statement Zen is built with security at every layer — and we’re clear about exactly what we keep and why.

Edge protection
Cloudflare
Card data
Handled by Stripe (PCI DSS L1)
Australian Privacy Principles
Aligned
EU GDPR
Aligned

What we keep, and why

What we keep
The statements you forward and the reconciliation results we produce from them, so your Statements history stays open to you.
Why we keep it
So you can reopen the original pages and the differences behind any reconciliation later, without forwarding the statement again.
What we don't hold
Card details never touch our servers — Stripe handles payments end to end. We don't collect financial data beyond what reconciliation requires, and we don't sell or share your data.

Transport & storage

Post-Quantum TLS
Application traffic to our API is protected with Cloudflare's hybrid post-quantum key exchange (ML-KEM) where the client supports it, with TLS 1.3 enabled and SSL set to strict — guarding your data against both current and future threats.
AES-256 Encryption at Rest
Stored data is encrypted at rest with AES-256 on managed AWS and Cloudflare services. The statements you forward and their reconciliation results are retained — encrypted — so you can reopen them any time in your Statements dashboard.
Cloudflare Edge + DDoS Protection
Application traffic is routed through Cloudflare's global edge, with DDoS protection and rate limiting safeguarding against attacks.

Access & payments

Role-Based Access + MFA
Authentication and identity run on Supabase Auth. Role-based access keeps team members scoped to what they need, and multi-factor authentication is available across accounts.
PCI DSS — handled by Stripe
All payments are processed by Stripe, a PCI DSS Level 1 payment provider. Statement Zen never stores, processes, or transmits card data.

Your data

Only What Reconciliation Needs
We hold your forwarded statements and their reconciliation results so your Statements history stays available to you, and we don't collect financial data beyond what reconciliation requires. We don't sell or share your data.
Privacy: APP + GDPR
Designed in line with the Australian Privacy Principles (APP) and the EU GDPR. We honour data-subject access and deletion requests and can provide details of our sub-processors on request.

Responsible Disclosure

Found a security vulnerability? We appreciate responsible disclosure. Please report issues to security@statementzen.com. We aim to acknowledge reports within two business days and will not take legal action against good-faith security researchers.

Serious security, self-serve simplicity

Start free — reconcile your first statement and see the differences in your Statements dashboard, no card required.