We're building Blueprint Ledger — sign up to get notified when we launch.

Security

Last updated: May 12, 2026

We know what we're asking customers to trust us with. Bank statements contain account numbers, balances, signatures on cancelled checks, and a near-complete picture of a business's finances. This page describes how we protect that information and the practices we hold ourselves to.

Encryption

  • All connections to and from the Service are encrypted in transit using TLS 1.2 or higher.
  • Internal links between the website and the extraction service are TLS-protected and authenticated with rotating API keys.
  • Connections from the public website to our processing infrastructure traverse a hardened tunnel and are not exposed on the public internet.

Authentication and access

  • Customers authenticate using third-party single sign-on providers. We never receive, see, or store your password.
  • Every internal API request must include a valid API key in addition to your user session.
  • Administrative access to production systems is restricted to authorized personnel and logged.
  • The processing service supports IP allowlisting, so the set of callers permitted to reach it can be restricted to the website service and known operator IP addresses.

Data residency and storage

  • All customer data is stored in the United States.
  • Uploaded PDFs, extraction results, and review submissions are kept so that customers can return to past extractions and re-export results. Customers may request deletion at any time.
  • Operational logs containing IP addresses and request timestamps are retained for up to twelve months and used for security monitoring, rate limiting, and debugging.

Use of customer data

  • We do not use customer-uploaded statements or extraction results to train our own or any third party's machine-learning models.
  • We do not sell or rent customer data. We do not share customer data with advertising networks.
  • We share data only with service providers necessary to operate the Service, and only for the purposes described in our Privacy Policy.

Sub-processors

  • We use a small number of third-party service providers in categories including hosting, identity, natural-language processing, and business directory lookup. Every sub-processor is bound by contract to handle data consistently with our Privacy Policy and applicable law, and none may use customer data to train their own models.
  • We perform diligence on each sub-processor before engaging it and review the security posture of existing sub-processors regularly.
  • Business customers may request our current list of named sub-processors and a Data Processing Agreement by emailing contact@blueprintledger.com.

Operational practices

  • The extraction service enforces per-IP rate limits to deter automated abuse.
  • Public API documentation is disabled in production — there is no browseable surface enumerating our endpoints.
  • Uploads larger than our published size limit are rejected at the edge.
  • Access events and processing activity are continuously logged and reviewed for anomalies.

Incident response

If we become aware of a personal-data breach affecting customer data, we will notify affected customers without undue delay, and in any event within seventy-two (72) hours of becoming aware, in accordance with applicable law and the commitments in our Data Processing Agreement. We will provide what we know about the nature of the incident, the data affected, the likely consequences, and the steps we are taking in response.

Reporting a vulnerability

If you believe you have discovered a security issue with the Service, we want to hear about it. Please email contact@blueprintledger.com with details, including steps to reproduce and any relevant logs or screenshots. We commit to:

  • Acknowledge your report within three business days;
  • Investigate and respond with a remediation plan or rationale;
  • Not pursue legal action against good-faith researchers who follow this process and avoid privacy violations, data destruction, and service disruption.

Questions

For questions about this page, security practices, or to request a Data Processing Agreement or named sub-processor list, contact:

Blueprint Ledger LLC
5900 Balcones Drive STE 100
Austin, TX 78731
contact@blueprintledger.com