Security & Privacy

Built for financial data. Serious about privacy.

CMB processes your statements and discards them. The workspace stores transactions, and only transactions. Here's exactly what that means.

SOC 2 Type II Certified Infrastructure  ·  PII auto-scrubbed, transactions only  ·  Bank statements deleted after extraction  ·  One-click client data deletion  ·  NDA-gated access

Security Principles

How we protect your financial data

SOC 2 Type II Certified Infrastructure

All automated processing runs through Anthropic's API, which is independently SOC 2 Type II certified, covering Security, Availability, and Confidentiality. Your financial data is processed through the same infrastructure Anthropic's enterprise customers use.

Never Used for Training

Anthropic's API explicitly excludes customer data from training by default. The transaction data, revenue figures, and expense breakdowns you provide cannot be used for training of any kind.

Bank Statements Deleted After Extraction

Uploaded PDF and CSV statements are held only while they are being processed, encrypted at rest and never in the bookkeeping database, then deleted as soon as extraction finishes. A file waiting on an answer from you is deleted after 24 hours. Only the extracted transaction records remain.

Transactions Only, No PII

The bookkeeping workspace stores transaction records (date, amount, category) to power the workspace. That's it. Descriptors are automatically scrubbed of Social Security numbers, phone numbers, email addresses, and ACH addenda name/ID fields before storage. No raw bank data persists.

NDA-Gated Access

Every bookkeeper and CPA who accesses client data must sign a Non-Disclosure Agreement before their account is activated. Access is reviewed and approved by an admin, with no self-serve access to client workspaces.

Encrypted in Transit and at Rest

All data is encrypted in transit via TLS 1.2+ and at rest via AES-256. Every interaction between your browser and our servers uses HTTPS exclusively. Financial data is never transmitted in plain text.

Bookkeeping Workspace

Transactions only. Zero PII.

The workspace stores transaction records (date, amount, description, category) to generate reports and sync with QuickBooks. No bank account numbers, no personal information, no raw statements. Everything else is discarded once extraction finishes.

One-click client deletion.Every client's transactions are scoped to that client alone. Delete a client and every transaction record, category, and audit log entry tied to them is permanently and immediately removed from our database.

What is stored

Transaction date

Date only, no timestamps or session metadata

Transaction amount

Numeric value only

Transaction description

Bank descriptor, scrubbed of detected PII before storage, used for vendor grouping

Category

Assigned by the bookkeeper or the engine, stored for reporting

Account type

Checking, savings, or credit card, used for reconciliation

What is never stored

  • ✓Bank account or routing numbers
  • ✓Raw PDF or CSV bank statement files (held in separate encrypted storage only until extraction finishes, never in this database)
  • ✓Employee names, salaries, or payroll details
  • ✓Tax IDs, SSNs, or legal entity identifiers
  • ✓Personal addresses, phone numbers, or email addresses
  • ✓SSNs, phone numbers, emails, or ACH addenda name/ID fields ("IND NAME:", "IND ID:") — automatically stripped from transaction descriptors before storage
  • ✓Data from other clients or other users

Data Lifecycle

What happens to your data over time

Bank statement uploadUntil extraction finishes

Your PDF or CSV is held in encrypted storage, separate from the bookkeeping database, while it waits its turn and while it is being extracted. The file is deleted as soon as extraction finishes. A file left waiting on an answer from you is deleted after 24 hours.

Transaction recordsUntil you delete them

Date, amount, description, and category are stored in your client workspace. You control this data: delete a client and all their records are permanently removed.

Anthropic API retentionUp to 30 days

Anthropic retains API requests and responses for trust and safety monitoring. This applies to automated categorization calls, and is separate from any consumer product.

After 30 daysPermanently deleted by Anthropic

Anthropic permanently deletes all retained API data. No financial data persists beyond this window at the Anthropic layer.

Enterprise & Compliance

Strict requirements? We can work with them.

For firms in regulated industries or with formal security review requirements, we can configure Zero Data Retention on processing calls, strip optional identifiers, provide Anthropic's SOC 2 report, or discuss data handling requirements specific to your engagement.

Note: Our platform is not currently HIPAA compliant, as Anthropic does not offer a Business Associate Agreement (BAA) at this time. It is also not suitable for EU data residency requirements without confirming region availability directly with Anthropic.