SECURITY — THE WORKING, SHOWN

Security at Offsetcheck

The most secure data is the data we never have. Offsetcheck is architected so your statements are processed on your device and never reach us.

LAST UPDATED 25 AUG 2026

Architecture that avoids the risk

Most breaches are of stored data. Offsetcheck stores none:

  • Client-side checking. Statement parsing (pdf.js, SheetJS) and all interest re-calculation run in your browser tab.
  • No upload endpoint. There is no API, server route or storage bucket that accepts statement files. Verify it in your browser's network inspector.
  • No accounts, no database. No sign-up means no credential store and no customer-data database to attack.
  • Nothing remembered. No cookies, local storage or server logs carry your figures. Close the tab, or press Clear my data, and the session is gone.

Controls in place

ACTIVE

Encryption in transit. The site is served over HTTPS by Cloudflare Pages; every page load is TLS-encrypted.

ACTIVE

On-device processing. Your files never traverse the network, so network-level interception of statement content is not possible.

ACTIVE

Data minimisation by design. The check needs only dates, descriptions, amounts and balances. We actively encourage you to redact names, addresses and account numbers before uploading.

PLANNED

Independent security review. A third-party review is planned before paid launch. We won't claim certifications we haven't earned — when one is completed, it will be named here with its date.

Third parties, listed

These are the only external services the site contacts, and what each receives:

Service Purpose What it receives
Cloudflare Pages Site hosting & TLS Standard web requests (page, IP for delivery)
Google Analytics 4 Anonymous usage analytics Page views and event names — never statement content
Google Fonts / cdnjs Typefaces & libraries Static asset requests only
FormSubmit Contact-form delivery Only what you type into the contact form

No advertising networks. No data brokers. No AI processing services.

What we ask of you

  • Redact identifiers. Black out names, addresses, BSBs and account numbers before uploading — the check works exactly the same without them.
  • Check the address bar. Use offsetcheck.com over HTTPS. We never email you asking for statements.
  • Keep your browser current. Your browser is the vault here; its updates matter.
  • Shared computers. Use Clear my data (or close the tab) when you're done. Exports you download are yours to protect.

Report a vulnerability

Found something? Tell us before you tell anyone else and we'll treat it as urgent:

  • Email contact@offsetcheck.com with the subject SECURITY
  • Include steps to reproduce, the page or file involved, and what you observed
  • Give us a reasonable window to fix before any public disclosure

We acknowledge reports within 2 business days. Machine-readable details live at /.well-known/security.txt.