Security

Protect the source. Limit what remains.

A telecom bill can contain names, contact details, account references, and usage information. Our design starts by treating that context as sensitive.

How the system is designed

Practical controls across the report lifecycle.

Security is a continuing operational responsibility—not a badge, buzzword, or single encryption claim.

01

Limited collection

The product asks for one supported telecom statement and only optional reading hints—not unrelated documents.

02

Transient source files

Source bill files are designed to be removed after processing, with short-lived technical copies limited to retries, security checks, and deletion workflows.

03

Controlled report access

Structured reports are kept separate from source files. Access requires a protected, expiring link; anyone who receives that link may be able to use it.

04

Purpose-limited providers

Stripe supports payment and OpenAI supports document interpretation and report drafting. Information is shared only as needed for those functions.

05

Operational safeguards

Access restrictions, environment separation, protected transport, credential controls, logging, and monitoring are used to reduce avoidable exposure.

06

Honest boundaries

No online system is risk-free. We avoid absolute claims and provide a direct path to report a suspected security problem.

Data lifecycle

The file and the report are not the same thing.

Keeping those artifacts separate makes it possible to remove the source while preserving the useful result you paid for.

  1. Upload

    A supported statement enters a private processing flow.

  2. Process

    Relevant content is read, structured, and returned with source evidence to review.

  3. Separate

    The structured report is stored independently from the source document.

  4. Remove

    The source file is deleted after processing and short-lived operational needs end.

You can reduce exposure, too

Share only the pages the report needs.

  • Do not upload payment cards, government IDs, passwords, or PINs.
  • Use only statements for an account you own or are authorized to manage.
  • Compare extracted fields with the original statement before acting on them.
  • Keep private report links to yourself.
  • Delete a report when you no longer need it.

Report a concern

Tell us without sending the sensitive material again.

Use Support and choose “Security concern.” Describe what happened, the approximate time, and the private report reference. Do not include the access token, passwords, full account numbers, card details, or a copy of the bill.