Security

Where your statements live, and who can read them

Perpetory asks for complete bank statements across every company you own. That deserves a straight account of how they are held, not a badge.

This page is the one item that genuinely blocks launch. The footer links to it from every page, and a dead or vague security link on a product like this says more than saying nothing would.

Five facts to confirm

Each needs a factual answer that can be defended a year from now. Where the honest answer is less impressive, publish the honest answer.

OPEN-01Which hosting provider and region?

Azure is the stated direction. Name the provider and the region, and say whether data ever leaves it.

OPEN-01Is data encrypted at rest as well as in transit, or TLS only today?

“TLS in transit, and not yet encrypted at rest” is a defensible answer. Implying at-rest encryption that does not exist is not.

OPEN-01Who can read customer data?

If the answer is “only the two founders, and only when a support request requires it”, that is a selling point — state it plainly, and say whether access is logged.

OPEN-01What happens on cancellation, and how long until data is actually gone?

Give a number of days, and be clear whether it means deleted or scheduled for deletion. Cross-check against the backup answer below, since a backup retains data after the live record is removed.

OPEN-01Backups: where, retained how long, encrypted or not?

Managed database backups usually contradict a short deletion window. Say how that is reconciled rather than leaving a reader to spot it.

What can be said already

Two claims hold today regardless of the answers above, because they follow from how the product is built rather than from an operational promise:

  • Perpetory never holds standing access to a bank account.There is no bank login and no aggregation feed. Statements arrive as files a user chooses to upload, so there is nothing to revoke on the way out.
  • No financial value or personal detail is sent to a third party, analytics included. Usage events record that a statement was imported, never what was in it.

Reporting a vulnerability

Mail hello@perpetory.com. Confirm this mailbox is monitored before the page goes live.