How BankScanPro handles financial documents.
Security claims should be specific enough to verify. This page explains the controls used by the current conversion service, where policy boundaries apply, and what commercial customers should confirm before sending production statements.
Current controls
Protection without absolute promises.
These controls describe the current service. They do not imply a security certification or a guarantee that every operational risk has been eliminated.
Encrypted transport and storage
PDFs travel over encrypted HTTPS connections and source/result artifacts use encrypted-at-rest cloud storage.
Separated product analytics
Statement contents stay outside product and marketing analytics while workflow events measure status and volume.
Financial data excluded from analytics
Workflow events may include page counts and status, but must not include filenames, account numbers, balances, payees, or transaction text.
Authenticated ownership
Conversion tasks and result routes are bound to authenticated users, with separate administrative controls for authorized operations.
Review-first delivery
Incomplete or weakly supported output is marked partial, needs review, or failed instead of being silently promoted to complete.
Document path
From upload to reviewed result.
- 01
Controlled upload
A visitor submits a PDF through an anonymous proof, an authenticated account, or a secure client request.
- 02
Non-public storage
The source file is stored under an internal object key rather than a public document URL.
- 03
Automated processing
Queue, extraction, validation, and contracted cloud/model services process the statement only to deliver the requested result.
- 04
Result and review state
The user receives structured rows together with page scope, validation, warnings, and export restrictions.
- 05
Controlled result access
Results remain available through the authenticated account or a time-limited secure result link.
What BankScanPro commits to publicly
- Documents are used to deliver the conversion.
- Financial document contents stay out of marketing analytics.
- Source and result access is controlled and non-public.
- Uncertain extraction is exposed through review and failure states.
What should be agreed separately
- Customer-specific data-governance requirements.
- DPA, subprocessor, residency, or procurement requirements.
- Contracted support, incident, or service-level targets.
- API credentials, webhook verification, and log controls.
- Any requirement for restricted operational access.
Security FAQ
Does product analytics contain statement data?+
No. Product events measure workflow state and volume without filenames, account numbers, balances, payees, or transaction text.
Can BankScanPro staff access documents?+
The product does not rely on routine manual review of uploaded statements. Access is restricted through application and infrastructure controls, but we do not make the absolute claim that authorized operational access can never occur. Contact support before uploading if your policy requires a specific access agreement.
What encryption is used?+
BankScanPro uses encrypted HTTPS transport and encrypted-at-rest cloud storage. Encryption details depend on the contracted infrastructure services in use; contact support if your policy requires a specific control statement.
Does BankScanPro provide a DPA?+
Eligible commercial customers can request a data processing agreement. API pilot customers scope DPA, subprocessor, access, and logging requirements before production access.
Need a commercial security review?
Tell us about your DPA, access, and workflow requirements before sending production data.