Security & data

Know where your data goes.

CashCatalyst asks you to upload financial records, so the data flow should be understandable. This page describes the current product without claiming certifications the service has not independently obtained.

Current controls

Practical safeguards in the application.

HTTPS production site

The production service is delivered over HTTPS. Authenticated session cookies are configured as HTTP-only and secure in production.

Organization-scoped records

Cash records are queried by organization. Team administration and invitations are restricted to eligible plans and administrator actions.

Request protection

State-changing application forms use CSRF protection, and sensitive authentication routes have rate limits.

No bank credentials requested

The current workflow uses uploaded statement exports. CashCatalyst does not ask for your online-banking username or password.

Data flow

What happens after an upload.

01

You select the file

The application accepts supported CSV, Excel, and standard PDF statement exports.

02

The file is parsed and classified

CSV and Excel data are parsed from their columns. PDF content and transaction text requiring AI classification may be sent to Anthropic as an AI service provider.

03

You review the proposed rows

Pending rows do not become organization transactions until a user confirms the import.

04

The confirmed ledger powers the product

Position, forecast, signals, insights, reports, and grounded assistant answers use organization-scoped records.

Service providers

External systems used for specific jobs.

ProviderPurposeWhat CashCatalyst does not store
Anthropic Supported PDF extraction, classification, daily brief, and assistant responses Not applicable; financial content needed for the requested AI operation may be processed
Stripe Paid-plan checkout and subscription billing CashCatalyst does not receive or store full payment-card details
Email provider Account verification, invitations, password reset, and service notifications Payment-card and bank-login details are not needed for these messages
Sentry, when enabled Application error monitoring It is not used as the cash ledger or statement store

Access, correction, or deletion requests

Contact [email protected]. We may need to verify the requester before acting on organization data.

Do not email sensitive files

Do not attach unredacted bank statements, passwords, payment-card details, or API keys to support messages.

This is a product security summary, not a certification. For privacy terms and user rights, read the Privacy Policy and Terms of Use.