Statement Poa

Trust

Security at Statement Poa

A precise description of the controls in the application today—and the boundaries we do not overstate.

Reviewed 21 July 2026

Current application controls

  • Hosted traffic is served over HTTPS, and account routes require authenticated sessions.
  • Statement product routes require an active account and verified email address.
  • Organisation and branch visibility is enforced in shared statement scopes and policies.
  • Local passwords are one-way hashed. Google-only accounts can reauthenticate with the same linked Google identity for sensitive actions.
  • A PDF password is used only to unlock the uploaded file and is not saved on the statement record.
  • Source files live in non-public application storage and are served only through authorised application routes.
  • Queue heartbeats, backlog thresholds, timeouts, and terminal job failures are logged and can notify an operations address.
  • Manual statement deletion removes the source file and related records. Optional retention removes completed statements after seven days.

Important boundary

Private storage is not an encryption-at-rest claim

Password-protected PDFs are decrypted into an ordinary readable copy for processing. The application does not currently add a separate encryption layer to that stored copy. The hosting filesystem may provide infrastructure-level controls, but Statement Poa does not represent that every statement file is application-encrypted at rest.

Retention and backups

Users can delete individual statements or their account. An opt-in preference marks completed statements for deletion seven days after processing. Statement-file deletion is enforced at the shared model boundary so web routes, bulk actions, account deletion, and scheduled retention use the same path.

Backup availability, encryption, geographic location, and rotation are properties of the active hosting deployment, not guarantees made by the application code. Request current deployment-specific information before relying on Statement Poa for an organisation with formal backup, residency, or encryption requirements.

External processing

Statement extraction runs in the application environment. Google sign-in, reCAPTCHA, email delivery, payments, and an optional OpenAI-backed audit classifier can send the limited data needed for those features to their providers. The optional classifier does not receive the source PDF; it receives normalised signatures by default, with raw transaction descriptions available only behind a separate administrator setting.

Customer responsibilities

Use a unique password, protect access to your Google account and email, grant support or organisation access only to people you trust, review branch memberships, and delete statements when they are no longer needed. Do not upload a statement unless you have authority to process every person’s information in it.

Report a security concern

Send a clear description, affected URL or feature, reproduction steps, and impact to support@statementpoa.com. Do not access or alter another person’s data, run disruptive tests, or include sensitive statement data in the initial report.