SECURITY — THE WORKING, SHOWN

Security at Offsetcheck

The most secure data is the data we never have. Offsetcheck is architected so your statements are processed on your device and never reach us.

LAST UPDATED 27 AUG 2026

Architecture that avoids the risk

Most breaches are of stored data. Offsetcheck stores none:

  • Client-side checking. Statement parsing (pdf.js, SheetJS) and all interest re-calculation run in your browser tab.
  • No upload endpoint. There is no API, server route or storage bucket that accepts statement files. Verify it in your browser's network inspector.
  • No accounts, no database. No sign-up means no credential store and no customer-data database to attack.
  • Nothing remembered. No cookies, local storage or server logs carry your figures. Close the tab, or press Clear my data, and the session is gone.

Controls in place

ACTIVE

Encryption in transit. The site is served over HTTPS by Cloudflare Pages; every page load is TLS-encrypted.

ACTIVE

On-device processing. Your files never traverse the network, so network-level interception of statement content is not possible.

ACTIVE

Data minimisation by design. The check needs only dates, descriptions, amounts and balances. We actively encourage you to redact names, addresses and account numbers before uploading.

ACTIVE

Content-Security-Policy with a locked-down network allowlist. Every page is served with a strict CSP. On the check page, browser network calls are limited to this origin and Google Analytics — nothing else. Even if malicious script somehow ran, the browser itself would refuse to send your data anywhere.

ACTIVE

Self-hosted, pinned libraries. The statement parsers (pdf.js, SheetJS) and every other script are served from our own deployment at pinned versions — no third-party CDN executes code on the page where your statements live.

ACTIVE

Output escaping. Everything parsed from a statement is HTML-escaped before it is displayed, so a crafted file cannot inject markup or script into the page.

PLANNED

Independent security review. A third-party review is planned before paid launch. We won't claim certifications we haven't earned — when one is completed, it will be named here with its date.

Third parties, listed

These are the only external services the site contacts, and what each receives:

Service Purpose What it receives
Cloudflare Pages Site hosting & TLS Standard web requests (page, IP for delivery)
Google Analytics 4 Anonymous usage analytics Page views and event names — never statement content
Google Fonts Typefaces Static font-file requests only — all JavaScript libraries are self-hosted
FormSubmit Contact-form delivery Only what you type into the contact form

No advertising networks. No data brokers. No AI processing services.

What we ask of you

  • Redact identifiers. Black out names, addresses, BSBs and account numbers before uploading — the check works exactly the same without them.
  • Check the address bar. Use offsetcheck.com over HTTPS. We never email you asking for statements.
  • Keep your browser current. Your browser is the vault here; its updates matter.
  • Shared computers. Use Clear my data (or close the tab) when you're done. Exports you download are yours to protect.

Report a vulnerability

Found something? Tell us before you tell anyone else and we'll treat it as urgent:

  • Email contact@offsetcheck.com with the subject SECURITY
  • Include steps to reproduce, the page or file involved, and what you observed
  • Give us a reasonable window to fix before any public disclosure

We acknowledge reports within 2 business days. Machine-readable details live at /.well-known/security.txt.