Security
Where your statements live, and who can read them
Perpetory asks for complete bank statements across every company you own. That deserves a straight account of how they are held, not a badge.
This page is the one item that genuinely blocks launch. The footer links to it from every page, and a dead or vague security link on a product like this says more than saying nothing would.
Five facts to confirm
Each needs a factual answer that can be defended a year from now. Where the honest answer is less impressive, publish the honest answer.
OPEN-01Which hosting provider and region?
OPEN-01Is data encrypted at rest as well as in transit, or TLS only today?
OPEN-01Who can read customer data?
OPEN-01What happens on cancellation, and how long until data is actually gone?
OPEN-01Backups: where, retained how long, encrypted or not?
What can be said already
Two claims hold today regardless of the answers above, because they follow from how the product is built rather than from an operational promise:
- Perpetory never holds standing access to a bank account.There is no bank login and no aggregation feed. Statements arrive as files a user chooses to upload, so there is nothing to revoke on the way out.
- No financial value or personal detail is sent to a third party, analytics included. Usage events record that a statement was imported, never what was in it.
Reporting a vulnerability
Mail hello@perpetory.com. Confirm this mailbox is monitored before the page goes live.