Security First Architecture

Bank-Level Security.
Zero Bank Access.

Your financial documents deserve the highest level of protection. We built PaperVault with security as the foundation—not an afterthought.

Our Core Security Principle

We never ask for your bank login credentials.Unlike Mint, Monarch, Copilot, and other budget apps that require Plaid connections, PaperVault takes a fundamentally different approach.

  • No Plaid, Yodlee, or similar bank connection services
  • No stored bank credentials anywhere in our system
  • You control exactly what data enters our platform
  • No third-party access to your financial accounts

How We Protect Your Data

Multiple layers of security work together to keep your documents safe.

Encryption in Transit

All data transmitted between your device and our servers uses TLS 1.3 encryption—the same standard used by banks.

Encryption at Rest

Your documents and data are encrypted using AES-256 encryption when stored, making them unreadable without proper keys.

Secure Authentication

Passwords are hashed using bcrypt with strong salt. We never store plaintext passwords. Optional 2FA adds another layer.

Row-Level Security

Database policies ensure users can only access their own data. Even in the event of a breach, data isolation is maintained.

Access Logging

All access to your data is logged and monitored for suspicious activity. You can review your account activity.

Secure Infrastructure

Hosted on AWS infrastructure with SOC 2 Type II certification. Regular security patches and updates applied.

Secure File Processing

Documents are processed in isolated environments. Files are scanned for malware before processing.

AI Processing Privacy

Your documents are NOT used to train AI models. Processing happens in real-time without persistent storage in AI systems.

Our Security Infrastructure

We partner with industry-leading providers who meet the highest security standards.

Supabase

Database & Storage

  • SOC 2 Type II certified
  • Hosted on AWS
  • Automatic backups
  • Point-in-time recovery

Vercel

Application Hosting

  • SOC 2 Type II certified
  • Global edge network
  • DDoS protection
  • Automatic HTTPS

Anthropic

AI Processing

  • No training on customer data
  • Data processing agreement
  • Encrypted API connections
  • No persistent storage

Compliance & Standards

We adhere to industry standards and regulations to protect your data.

GDPR

EU data protection compliance

CCPA

California privacy compliance

SOC 2

Via our infrastructure partners

HTTPS

TLS 1.3 encryption everywhere

Your Data Rights

You maintain full control over your data at all times.

Access

View and download all your data at any time through your account settings.

Portability

Export your documents and data in standard formats (CSV, PDF) anytime.

Deletion

Request complete account and data deletion. We honor all requests within 30 days.

Our Security Practices

Security is an ongoing commitment, not a one-time effort.

Regular Updates

We continuously update our dependencies and apply security patches. Our infrastructure is automatically updated with the latest security fixes.

Minimal Access

We follow the principle of least privilege. Only essential personnel have access to production systems, and all access is logged and audited.

Incident Response

We have documented incident response procedures. In the unlikely event of a security incident, we will notify affected users promptly.

Security Testing

We perform regular security assessments and vulnerability scanning. Critical issues are addressed immediately upon discovery.

Report a Security Issue

We take security seriously. If you discover a security vulnerability, please report it responsibly. We appreciate your help in keeping PaperVault secure.

security@papervault.one

Please include detailed information about the vulnerability. We will acknowledge receipt within 24 hours and provide updates on our investigation.

Security FAQ

Do you store my bank login credentials?

No, never. We never ask for or store bank login credentials. Unlike apps that use Plaid, we use a document-based approach where you upload statements rather than connecting accounts.

Can PaperVault employees see my documents?

Access to customer data is strictly limited. Only essential personnel with legitimate business needs can access production data, and all access is logged. We do not review customer documents except when explicitly requested for support.

Is my data used to train AI models?

No. Your documents are processed by Anthropic's Claude API to extract financial data, but they are NOT used to train AI models. Anthropic's data processing agreement explicitly prohibits training on customer data.

What happens if I delete my account?

All your data, including documents and extracted information, is permanently deleted within 30 days. Encrypted backups may persist for up to 90 days before automatic expiration.

Do you sell my data to third parties?

Absolutely not. We do not sell, rent, or trade your personal information or document data. Your data is used solely to provide you with our services.