Security
Where your statements live, and who can read them
Perpetory asks for complete bank statements across every company you own. That deserves a straight account of how they are held, not a badge.
This page is the one item that genuinely blocks launch. The footer links to it from every page, and a dead or vague security link on a product like this says more than saying nothing would.
Where it runs
Perpetory runs on Microsoft Azure in the United States, on managed services rather than servers we patch ourselves. That is a security statement and not a procurement one: it means database patching, backups and infrastructure access control are Azure’s responsibility under their operational controls rather than ours under a maintenance window we might miss.
Cloudflare sits in front of both this site and the application, terminating TLS and absorbing denial-of-service traffic.
Your data is stored and processed in the United States. The deliberate wording is “stored and processed” rather than “never leaves”: Cloudflare terminates TLS at whichever edge is nearest the person connecting, so a request from Europe is decrypted in Europe before reaching a US origin. Everything that is kept, is kept in the United States.
We deliberately do not publish region codes, database versions, infrastructure topology or how our own access is tooled. None of it helps you decide whether to trust us, and it is the detail that belongs in a security questionnaire. Ask and we will answer it directly.
Encryption
In transit. Every connection is over TLS: your browser to Cloudflare, Cloudflare to our servers, and our application to the database. Plain HTTP is redirected, never served.
At rest. Your data is encrypted on disk with AES-256, using keys the Azure platform manages. This is not something we switched on - on Azure’s managed database it is always on and cannot be turned off, and that includes the automated backups. So there is no window in which a disk or a backup file holds your statements in the clear.
To be precise about what we do not do: the keys are Azure’s, not ours. Customer-managed keys - where you hold the key in a vault and can revoke it - are available on this infrastructure and we have not set them up, because nothing about our size would make that a real improvement today. If your situation requires it, ask.
“Bank-level encryption” is a phrase we will not use. It means nothing. The paragraphs above are the whole of it.
Who reads your data
Nobody, unless you ask us to. There is no routine access to customer data - no dashboard anyone browses, no analytics run across accounts, nobody looking at your categorizations to see how the product is doing. If you write to us about something that requires looking at your account, we look at your account, for that, and then stop.
Encryption at rest protects against a stolen disk. It does nothing about a person with a database connection, which is why this paragraph matters more than the one above it. Most companies answer this with “authorized personnel”, which is a way of not answering.
Categorization and the written analysis use a language model, which is not a person but is worth being straight about: it runs in our own Azure subscription and is given transaction text with your identity stripped out first. The privacy policy sets out exactly what it does and does not receive.
Backups, cancellation and erasure
Backups are automated by Azure, held in the same United States region as the database, and encrypted under the same always-on encryption. They are kept for 30 days, which is what makes recovery from a bad day possible and is also the outer bound on erasure.
If you cancel, your data is kept for 30 days so that an accidental cancellation is recoverable and you can still export. After that the account and everything in it is deleted.
If you ask us to delete everything, we do it when you ask - not at the end of a window. The live data is gone that day.
In both cases backups are the lag, and we would rather do the arithmetic for you than let you find it. Deletion removes the live record; the encrypted backups containing it then age out over the following 30 days. So an explicit deletion request means everything is gone within 30 days, and a cancellation left to run its course means up to 60 days - the grace period and the backup window, one after the other. Nothing remains after that.
Data & deletion covers how to ask, and how to get everything out first.
Two more things that hold
Both follow from how the product is built rather than from an operational promise:
- Perpetory never holds standing access to a bank account. There is no bank login and no aggregation feed. Statements arrive as files a user chooses to upload, so there is nothing to revoke on the way out.
- No financial value or personal detail is sent to a third party, analytics included. Usage events record that a statement was imported, never what was in it.
Reporting a vulnerability
Mail [email protected]. We will acknowledge it, and we would rather hear from you than not.