Ledger Tome

Security

What happens to a bank statement after you upload it: where it is stored, who processes it, and when it is deleted.

This page summarises how the service is built. The Privacy Policy is the document that governs, and it is more detailed. Last updated 15 August 2026.

Storage and encryption

Where your files are stored
Our primary infrastructure runs on AWS in the EU (Ireland), with the website delivered through CloudFront's edge network. Uploaded documents and generated output files are stored in object storage in that region.
Encryption
All traffic to and from the service uses TLS. Stored files are encrypted at rest with AES-256 server-side encryption.
Access to the storage
The storage buckets holding uploads and outputs block public access and are reachable only through identity-restricted access from our own services. Download links handed to your browser are time-limited and signed for a single file.
Accounts
Authentication runs on AWS Cognito. Passwords are hashed, and Google Sign-In is available if you would rather not have a password with us at all.
What we never ask for
We do not connect to your bank. There is no place in the product to enter online banking credentials, and no integration that would use them. You give us a file.

Retention and deletion

Uploaded documents
Deleted automatically seven days after upload. This is enforced by a storage lifecycle rule rather than by a scheduled job, so it happens whether or not anything else is working.
Converted output files
The same seven days from generation. That window is what makes the conversion history re-downloadable; after it, the files are gone.
Deleting sooner
Deleting a conversion from your history removes the output file, the metadata beside it and the original document you uploaded, without waiting for the seven days.
Files you attach to feedback
Kept for up to 30 days, then deleted.
Your account
You can delete it from the dashboard. Deletion removes your remaining files and your per-account records within 30 days; the Privacy Policy sets out exactly what is kept and why.

AI processing

What is sent
Converting a PDF means sending the document to an AI provider for extraction. That is the core of how the product works, and it is worth understanding before you upload anything sensitive.
Training
The providers we use are contracted so that inputs and outputs are not used to train or fine-tune their models, and are not retained beyond returning the result to us. Providers may keep their own request metadata, such as volumes and timestamps, for security and abuse monitoring.
Where it happens
Depending on the provider, processing may take place in the EU or in the United States. For transfers outside the EU we rely on the safeguards set out in the Privacy Policy.
Current AI providers
Anthropic (extraction, United States with global routing), Fireworks AI (document processing, United States), Datalab (OCR, United States) and Mistral AI (document processing, EU). The Privacy Policy carries the full sub-processor list, including payment, email and analytics providers, and is updated when it changes.

What this page does not claim

Worth stating plainly, because security pages tend to imply more than they say.

  • We hold no third-party security certification. There is no SOC 2 report, no ISO 27001 certificate and no published penetration test.
  • We do not claim that no person could ever access an uploaded document. Access is restricted to our own services, and we do not read customer statements as a matter of course, but we do not publish a formal access-control policy you could hold us to.
  • No system is perfectly secure. If a personal data breach affecting you occurs, we will notify you and the relevant supervisory authority as the law requires.

Reporting something

If you think you have found a security problem, email info@ledgertome.com with enough detail to reproduce it. We would rather hear about it early and awkwardly than late.

Cookies and analytics

We use necessary cookies to keep Ledger Tome working, and with your consent we use marketing and analytics cookies to improve it. You can change this anytime in Settings or our Privacy Policy .