Security & Privacy
CMB processes your statements and discards them. The workspace stores transactions, and only transactions. Here's exactly what that means.
SOC 2 Type II Certified Infrastructure · PII auto-scrubbed, transactions only · Bank statements deleted after extraction · One-click client data deletion · NDA-gated access
Security Principles
All automated processing runs through Anthropic's API, which is independently SOC 2 Type II certified, covering Security, Availability, and Confidentiality. Your financial data is processed through the same infrastructure Anthropic's enterprise customers use.
Anthropic's API explicitly excludes customer data from training by default. The transaction data, revenue figures, and expense breakdowns you provide cannot be used for training of any kind.
Uploaded PDF and CSV statements are held only while they are being processed, encrypted at rest and never in the bookkeeping database, then deleted as soon as extraction finishes. A file waiting on an answer from you is deleted after 24 hours. Only the extracted transaction records remain.
The bookkeeping workspace stores transaction records (date, amount, category) to power the workspace. That's it. Descriptors are automatically scrubbed of Social Security numbers, phone numbers, email addresses, and ACH addenda name/ID fields before storage. No raw bank data persists.
Every bookkeeper and CPA who accesses client data must sign a Non-Disclosure Agreement before their account is activated. Access is reviewed and approved by an admin, with no self-serve access to client workspaces.
All data is encrypted in transit via TLS 1.2+ and at rest via AES-256. Every interaction between your browser and our servers uses HTTPS exclusively. Financial data is never transmitted in plain text.
Bookkeeping Workspace
The workspace stores transaction records (date, amount, description, category) to generate reports and sync with QuickBooks. No bank account numbers, no personal information, no raw statements. Everything else is discarded once extraction finishes.
One-click client deletion.Every client's transactions are scoped to that client alone. Delete a client and every transaction record, category, and audit log entry tied to them is permanently and immediately removed from our database.
Transaction date
Date only, no timestamps or session metadata
Transaction amount
Numeric value only
Transaction description
Bank descriptor, scrubbed of detected PII before storage, used for vendor grouping
Category
Assigned by the bookkeeper or the engine, stored for reporting
Account type
Checking, savings, or credit card, used for reconciliation
Data Lifecycle
Your PDF or CSV is held in encrypted storage, separate from the bookkeeping database, while it waits its turn and while it is being extracted. The file is deleted as soon as extraction finishes. A file left waiting on an answer from you is deleted after 24 hours.
Date, amount, description, and category are stored in your client workspace. You control this data: delete a client and all their records are permanently removed.
Anthropic retains API requests and responses for trust and safety monitoring. This applies to automated categorization calls, and is separate from any consumer product.
Anthropic permanently deletes all retained API data. No financial data persists beyond this window at the Anthropic layer.
Enterprise & Compliance
For firms in regulated industries or with formal security review requirements, we can configure Zero Data Retention on processing calls, strip optional identifiers, provide Anthropic's SOC 2 report, or discuss data handling requirements specific to your engagement.
Note: Our platform is not currently HIPAA compliant, as Anthropic does not offer a Business Associate Agreement (BAA) at this time. It is also not suitable for EU data residency requirements without confirming region availability directly with Anthropic.