Skip to content
Trust

Security

Where your documents go, how long they stay, who can reach them, and what happens when something breaks — the answers a compliance review asks for, in one place.

Last updated 2 September 2026

The short version

The documents you send us are the most sensitive thing on this platform, and usually they are not even about you — they belong to a loan applicant who has trusted somebody else with them. Three commitments follow from that, and the rest of this page is how they are kept.

  • Your documents are used to produce your report, and for nothing else.
  • They are not used to train machine-learning models, by us or by anyone we send them to.
  • They are deleted on a schedule rather than kept because storage is cheap.

In transit

Every connection to the website, the web application and the API is served over HTTPS, and plain HTTP is redirected to it. Certificates are issued and renewed automatically, so there is no window in which the site falls back to an unencrypted connection.

The documents themselves

  • An uploaded file is stored so that you can re-download it and audit a report you have already paid for, and is scoped to the account that uploaded it. Another customer cannot reach it, and neither can another account in the same organisation unless your administrator has put them on your account.
  • PDF passwords are not stored. The password you supply is held only for as long as it takes to open the file, and is never written alongside the document.
  • Uploads and the reports generated from them are deleted automatically after 90 days by default. An organisation on an enterprise agreement may have a different window; your administrator will know which.

Accounts and sessions

  • Passwords are stored only as salted hashes. We cannot read yours, and neither can anyone who obtains the database.
  • Signing in creates a session token held in a cookie. It is the only cookie we set, and clearing it signs you out.
  • Optional email verification and Google sign-in are both available. Google sign-in uses Google's own token flow — we hold only a public client ID, never a secret, and never your Google password.
  • A password-reset email always points at our own published address, taken from a setting rather than from whoever asked for the reset. That is what stops a stranger having our mail carry a link to their page.
  • Reports, credits and the ledger belong to the account rather than to one person, so what a colleague can see is what your administrator has granted, not whatever they can guess a URL for.

AI processing

Most statements are parsed by our own code on our own servers. A scan, a photograph or a layout we have not seen before is sent to a third-party AI model to be read — depending on the document, Anthropic, OpenAI, Google, Mistral or Amazon Web Services (Bedrock). Under their business terms these providers do not train on what we send them.

If you would rather no document of yours ever left our servers that way, write to support@zyxw.in and we will switch AI processing off for your account. Documents we cannot read without it will then fail rather than be sent onward — which is the trade, stated plainly.

Who can reach production

Access to production systems is limited to the people who operate them. Support work is done against your account only to answer a request you have made or to investigate a fault you have reported. Ordinary web and application logs, which include IP addresses and request paths, are kept for a short operational period for exactly that purpose and then rotated away.

What we deliberately do not do

  • No advertising, analytics or session-recording trackers on this site — which is why you are not asked to accept a cookie banner.
  • No selling of your data, and no sharing of it for advertising.
  • No training of models on your documents or on anything derived from them.
  • No card details on our servers. Credits are bought by transferring the money from your own bank's app; nothing on this platform can move money out of your account. See Refunds.

If something goes wrong

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authority as the law requires, and tell you what was affected rather than only that something was.

Reporting a vulnerability

If you think you have found a vulnerability, write to support@zyxw.in with enough detail to reproduce it, and please give us a chance to fix it before disclosing it publicly. We will not pursue anyone who reports a genuine finding in good faith and does not access, alter or retain other people's data while doing so.

Please do not test with real customer documents, run automated scans that degrade the service for others, or attempt social engineering against our staff or suppliers.

Where the detail lives

The Privacy Policy is the authoritative account of what we collect and how long we keep it, including your rights under the Digital Personal Data Protection Act, 2023. The Terms of Service set out what you may upload and the basis on which you may upload somebody else's statement.

Reviewing us as a vendor?

Write to support@zyxw.in and we'll get back to you.