Finance Secretary — Security & Data Protection

Last reviewed: May 2026
Published by AI Secretary Limited (trading as AISec Technology), company number 17245992, registered in England and Wales.
Security contact: [email protected]

In short. Your financial data lives on your own device, not on our servers. Document classification runs on private AI hardware we own in the United Kingdom — never a third-party cloud. There is no advertising, no analytics, and no tracking. This page explains how we protect your information and how to report a security concern.

1. Where your data lives

2. How information is protected

3. The private AI classification step

When you upload a PDF or image, the text is read on your device using Apple's Vision framework. Only that extracted text — never the original file, your name, email, or password — is sent over HTTPS to our private AI service at api.aisectech.uk. The service runs on hardware we own, in our own location; it is not a third-party cloud. The text is held only briefly to complete the job, then automatically purged. It is not logged, not used to train any model, and never shared outside our own infrastructure.

4. What we deliberately don't do

5. What we design against

Our security work is built around a written threat model. The main risks we design for, and the protections that address each:

Like any consumer application, Finance Secretary is not designed to withstand state-level adversaries or an attacker who has already compromised your device's operating system.

6. Ongoing review

We carry out a security review before each major release and re-audit after significant changes — covering authentication, data storage, transport, the AI pipeline, and dependency advisories. Where a review identifies something to harden, we fix it before shipping rather than publish a live list of open issues. We're happy to discuss our practices with security researchers.

7. Reporting a security issue

If you believe you've found a vulnerability or a privacy problem, please email [email protected] with enough detail for us to reproduce it. We'll acknowledge your report, investigate, and keep you updated. Please give us a reasonable opportunity to resolve the issue before disclosing it publicly. We don't currently run a paid bug-bounty, but we're grateful for responsible disclosure and will credit you if you'd like.

© 2026 AI Secretary Limited. See our privacy policy, support page, or return to product home.