Security and data handling

You are asked to upload bank statements and receipts, so this page answers the questions a finance team should ask before doing that. Where something is not yet in place, it says so.

Where data is stored

The Service runs on Railway in its United States region, on a persistent volume attached to the application. Each organisation's data (funds, learned rules, runs, reports, snapshots) is kept in its own directory and every request is scoped to the signed-in user's organisation.

Encryption

All traffic between your browser and the Service, and between the Service and its processors, is encrypted with TLS. Data at rest relies on the hosting provider's storage; the application does not add a second layer of encryption on top of it.

What the AI provider receives

Statement page images and receipt photos are sent to OpenAI's API to be read, and short text snippets are sent for category suggestions and wording. This is API use: under OpenAI's API terms the data is not used to train models, and OpenAI may retain API inputs for up to 30 days for abuse monitoring before deletion. No other AI provider receives your data.

Retention and deletion

Access control

Who at Ermaz LLC can see your data

Operational access to the hosting environment is limited to what is needed to run the Service and to act on your support requests. We do not look at your documents for any other purpose and we do not sell or share them.

Payments

Card details are entered on Paddle's checkout and never reach our servers. We store only your plan, status, renewal date and Paddle identifiers. Paddle's webhooks are verified by signature and protected against replay and out-of-order delivery.

What is recorded

Each organisation has an event history for billing and settings changes. Every edited report line records who confirmed it and when. A downloadable audit trail per report and an organisation-wide activity log are planned but not yet available.

Certifications and agreements

Ermaz LLC does not currently hold SOC 2, ISO 27001 or similar certifications. A data processing agreement is available on request for organisations that require one.

Reporting a concern

Email support@honestrecord.com. Security reports are acknowledged within two business days.

Last updated 23 August 2026.