Security

Security and Local Processing

How local file processing works and what to verify before export.

Where your file goes

Public tools read, parse and export the selected statement in the browser tab. The supported workflow does not intentionally send statement contents to the Bank File Flow server.

PDF passwords and reset

A PDF password is used locally and is not intentionally transmitted, logged or saved to persistent browser storage. Reset, cancellation and errors clear the page’s working reference, but no website can guarantee deletion from every browser or operating-system layer.

File, page and processing limits

Bank and accounting tools accept one file up to 10 MB on every plan. PDF Editor keeps its separate plan limits: 2 MB on Free and 25 MB on Pro. PDF processing also has a 200-page ceiling. Conversion tools reject scanned or photographed PDFs because optical character recognition is not implemented; the PDF Editor can display and annotate them but does not claim to edit their scanned words.

PDF editing and export

The PDF Editor uses local copies of PDF.js for rendering and pdf-lib for writing a new file. It never overwrites the original. Edited export is disabled after opening a password-protected PDF because the writer cannot preserve its encryption, and the editor warns when common digital-signature markers are detected.

Formula-like spreadsheet text

Spreadsheet apps may treat text beginning with =, +, - or @ as a formula. Documented free-text fields are escaped before export; still review unfamiliar descriptions.

Your device and download

Use an updated browser on a trusted device. Compare transaction count, dates, totals and flagged rows with the original statement, then close the tab and secure the downloaded CSV.

Reporting a security concern

A dedicated security address has not yet been published. Use a verified contact method when available and share only synthetic reproduction data—never a real statement, account number, card number or password.