Phase 1 architecture

What happens in the browser – and what stays in the hosted service.

In the hosted tool, statement and Schedule A files are processed in your browser and are not uploaded to the Statement Forensics backend. Internet access is required to sign in and load the authorized rate vintage. The browser may retain selected workflow preferences or derived verification state until the user clears that account’s local data or clears the site’s browser data.

Merchant statement

Browser-local. The user selects the processing statement in the authenticated tool. The Phase 1 backend has no statement-upload endpoint and does not receive the statement file or extracted statement text.

Authentication & entitlement

Hosted. Account credentials establish an authorized session. The service determines whether the account may launch the tool and receive the currently authorized rate vintage.

Rate vintage

Server to browser. The authorized, immutable rate package is delivered with the protected tool and used by the local audit engine. A copied snapshot can contain the vintage it received, but it does not receive future maintained vintages without authorized access.

Watermark identity

Per account. The protected build is stamped with an account-specific licence identity for attribution and deterrence. It is not represented as copy prevention.

User browser
Statement + Schedule A stay here
PDF/XLS/CSV parsing · OCR · audit · report
Statement Forensics hosted service
Sign-in · entitlement · watermark identity · authorized rate vintage

Connectivity: Phase 1 requires an internet connection for authentication and authorized rate-vintage delivery. The accurate claim is that statement content is not uploaded to Statement Forensics – not that the application makes no network requests.

Future features: billing, analytics, account history, support uploads or any server-side statement feature must be reviewed separately before deployment because they can change this boundary.