Security you can trust
Your financial data deserves serious protection. Statement Zen is built with security at every layer — and we’re clear about exactly what we keep and why.
- Edge protection
- Cloudflare
- Card data
- Handled by Stripe (PCI DSS L1)
- Australian Privacy Principles
- Aligned
- EU GDPR
- Aligned
What we keep, and why
- What we keep
- The statements you forward and the reconciliation results we produce from them, so your Statements history stays open to you.
- Why we keep it
- So you can reopen the original pages and the differences behind any reconciliation later, without forwarding the statement again.
- What we don't hold
- Card details never touch our servers — Stripe handles payments end to end. We don't collect financial data beyond what reconciliation requires, and we don't sell or share your data.
Transport & storage
- Post-Quantum TLS
- Application traffic to our API is protected with Cloudflare's hybrid post-quantum key exchange (ML-KEM) where the client supports it, with TLS 1.3 enabled and SSL set to strict — guarding your data against both current and future threats.
- AES-256 Encryption at Rest
- Stored data is encrypted at rest with AES-256 on managed AWS and Cloudflare services. The statements you forward and their reconciliation results are retained — encrypted — so you can reopen them any time in your Statements dashboard.
- Cloudflare Edge + DDoS Protection
- Application traffic is routed through Cloudflare's global edge, with DDoS protection and rate limiting safeguarding against attacks.
Access & payments
- Role-Based Access + MFA
- Authentication and identity run on Supabase Auth. Role-based access keeps team members scoped to what they need, and multi-factor authentication is available across accounts.
- PCI DSS — handled by Stripe
- All payments are processed by Stripe, a PCI DSS Level 1 payment provider. Statement Zen never stores, processes, or transmits card data.
Your data
- Only What Reconciliation Needs
- We hold your forwarded statements and their reconciliation results so your Statements history stays available to you, and we don't collect financial data beyond what reconciliation requires. We don't sell or share your data.
- Privacy: APP + GDPR
- Designed in line with the Australian Privacy Principles (APP) and the EU GDPR. We honour data-subject access and deletion requests and can provide details of our sub-processors on request.
Responsible Disclosure
Found a security vulnerability? We appreciate responsible disclosure. Please report issues to security@statementzen.com. We aim to acknowledge reports within two business days and will not take legal action against good-faith security researchers.
Serious security, self-serve simplicity
Start free — reconcile your first statement and see the differences in your Statements dashboard, no card required.