Skip to main content
Convert·Into
Security & privacy

Your clients' statements, handled to banking standards.

We built this for accountants, auditors and lawyers who cannot afford a data incident. Encryption end to end, isolation per file, and deletion on your command: by default, on every plan.

256-bit
AES encryption
TLS 1.3
encrypted in transit
0
files sold or trained on
  • BANK-GRADESECURITY
  • DATAPRIVACY
  • GDPRCOMPLIANT
  • AES256-BIT
A file's lifecycle
  1. Uploaded over TLS 1.3
    The file travels from your browser inside a 256-bit encrypted session. It is never sent in the clear.
  2. Processed in isolation
    Extraction runs in a sandboxed, single-tenant worker. Your file is never co-mingled with another firm’s data.
  3. Delivered to you only
    The resulting XLSX, CSV or QBO/OFX file is returned to your session. We do not read, sell or train on your financial data.
  4. Deleted on your command
    Remove a file and both the source PDF and its output are wiped immediately. Nothing is kept longer than you need it.
How we protect data

Security isn't a feature here; it's the architecture.

  • ENCRYPTION

    Encrypted in transit & at rest

    TLS 1.3 on the wire and AES-256 on disk. Keys are managed in a hardware security module, rotated regularly.

  • ISOLATION

    Single-tenant processing

    Each conversion runs in its own ephemeral, sandboxed environment that is destroyed when the job completes.

  • RETENTION

    You control retention

    No indefinite storage. Delete files the moment you are done, and Professional and Enterprise teams can set custom retention windows to match their compliance policy.

  • ACCESS

    No credentials, least privilege

    We never ask for online-banking logins. Internal access is role-scoped, logged and reviewed quarterly.

  • PRIVACY

    Your data is never the product

    We do not sell data or use your statements to train models. What you convert is yours alone.

  • RESILIENCE

    Monitored & backed up

    Infrastructure is continuously monitored, with encrypted backups and a tested incident-response plan.

Compliance

Enterprise-grade controls, audit-ready.

Certifications and controls your compliance team already knows: documentation available under NDA on Professional and Enterprise plans.

  • Bank-grade security
    Encryption in transit and at rest, per-file isolation
  • Data privacy
    Never sold, never used to train models
  • GDPR
    EU & UK data protection
  • PCI-aware
    Card-data handling controls

Our commitments to you

Plain-English promises, not buried in a policy.

  • We will never sell your data
    Not to advertisers, data brokers, or anyone. Your statements exist only to produce your export.
  • We will never train models on your files
    Your financial data is excluded from any model training or analytics dataset.
  • We will delete on request, immediately
    One click removes your files and their parsed data for good, no questions asked.
  • We will tell you if something goes wrong
    In the unlikely event of an incident, affected customers are notified promptly and transparently.
  • We will keep our sub-processors short and public
    A current list of infrastructure sub-processors is available on request, kept deliberately minimal.

Found something? Report it responsibly at security@convertin.to

Convert with confidence.

Bank-grade security on every conversion: files are encrypted, processed in isolation and never used to train models.