Skip to content
Security & trust

Who can see your clients' documents? Vendor access, compared

By Chris Wattinger, Technology Lead at Scale CPA · Reviewed by Howard Telson, CPA, MST · Published · 7 min read
securityprivacy

Here is the direct answer: it depends on where the files end up. When a statement-retrieval or document-collection tool stores your clients’ documents on the vendor’s own servers, people who work at that vendor can usually open them. Support tooling exists for a reason, and in a vendor-hosted product, the reason is your files. When the tool delivers documents into storage your firm controls and keeps no copy, there is nothing on the vendor’s side for anyone to browse.

That one architectural choice decides most of what matters for client document privacy. Everything else, the certifications, the access policies, the NDAs, sits on top of it. So before you compare feature lists, ask each vendor a single question: where does the PDF live after you fetch it?

Two places a client statement can live

The vendor’s archive. Most document tools for accountants work this way. The software fetches or receives files, stores them in the vendor’s cloud, and presents them back through the vendor’s app. Hosted tools typically offer conveniences like in-app previews, search, one login for your whole team, and a support desk that can fix a misfiled statement quickly because they can look at the actual file. As hosted products, LedgerSync and LedgerDocs both keep documents on the vendor’s side, and both are established products with years in market.

The costs are just as real. The vendor’s employees are now inside the circle of people who can reach your clients’ financial documents, governed by that vendor’s internal policy rather than yours. Leaving means an export and migration project. And under your security obligations (more on those below), you are now responsible for assessing their staff-access controls, their logging, and their retention, every year, for as long as you use them.

Your own storage. The tool acts as a courier. It fetches the statement, verifies it, drops it into a Drive or SharePoint your firm already controls, and keeps operational metadata rather than documents. Your existing permissions, retention policy, and staff-offboarding checklist keep applying, because the files never left your estate.

The trade-off deserves to be said out loud: a courier-style vendor’s support team cannot pull up your PDF to eyeball a problem. Diagnosis happens from logs and metadata. Slightly slower for a few support cases. Structurally better for privacy.

Vendor-hosted archiveYour own storage
Where the PDF livesVendor’s cloudYour firm’s Drive or SharePoint
Who can open itYour team, plus vendor staff per their policyWhoever your firm has granted access
When you cancelExport and migration projectFiles were always yours
Safeguards oversightYou assess their staff-access controlsYou assess a delivery pipe

What public reviews actually say

A named example makes this concrete. LedgerSync is a mature, established statement-retrieval tool for accountants with years in market: 10,000+ banks via Mastercard Open Banking and MX, transaction fetching, check images, and direct pushes into QuickBooks Online, QuickBooks Desktop, Zoho Books, and Accounting CS. Those are genuine strengths, and several of them are things StatementFlow does not do at all.

On the access question, though: reviewers on G2 and Capterra report that LedgerSync support staff can view fetched documents. Nobody is alleging misuse. Hosted archives work this way by design; support can see files because support was built to see files. The question for your firm is whether you knew that, whether your engagement letters and security program account for it, and whether your clients would be comfortable if you explained it to them. We compare the two architectures in more depth in StatementFlow vs LedgerSync.

Two related notes for firms shopping in this category. Hubdoc retired its statement Auto-Fetch feature in early 2022, so it no longer fetches bank statements automatically at all; documents you upload to it live in Hubdoc’s system, integrated with Xero. LedgerDocs treats statement fetching as an add-on to a broader vendor-hosted document management product, which is a sensible design for its purpose but keeps the archive on their side.

How we built StatementFlow

We run an accounting firm. StatementFlow was built inside Scale CPA to fetch statements for our own client book before anyone else’s, which meant we had to answer the vendor-access question for ourselves first. The storage decision came out simple: the firm’s archive should belong to the firm.

The flow: each client connects their bank once through a secure invite link, authenticating at their own bank via Plaid or Mastercard Open Banking. Nobody at the firm and nobody at StatementFlow ever sees credentials. When the bank publishes a statement, we retrieve the official PDF (Plaid documents this in its statements API), verify the download against its SHA-256 hash, and file it into the firm’s own Google Drive, organized by client, year, and month. The same pipeline handles settlement statements from processors like Stripe, PayPal, Square, and Shopify.

What lives on our side: encrypted connection tokens (AES-256-GCM at rest), refresh-job status, the coverage grid, and a full audit log. What does not live on our side: your documents. There is no internal admin screen where someone on our team pages through client statements, because the statements sit in your Drive, behind your permissions.

Two honest caveats.

First, Google still hosts that Drive, under your firm’s Workspace agreement and your admin console. You made that vendor decision long before you met us, and you govern it. StatementFlow declines to become a second archive on top of it.

Second, we are in early access, and we will not wave around certifications we do not have. What we can describe today: bank-side authentication, signature-verified webhooks, role-based access for firm staff, passkey step-up before sensitive actions, and an audit log of who did what and when. The details are on our security page. We are equally plain about scope: no OCR or data extraction (that is Dext, AutoEntry, and DocuClipper territory), no bookkeeping engine, US banks only.

Questions worth asking any vendor

Whichever tool wins your evaluation, get these answered in writing before a single client connects:

  1. Where exactly are client documents stored, and for how long?
  2. Which of your employees can view client documents, and under what policy? “Only with permission” is a start; ask what technically enforces it.
  3. Is every staff access to a client file logged, and can we request that log?
  4. Do you have a current SOC 2 Type II report? If not, what compensating controls exist, and when is one expected?
  5. Who are your subprocessors, and where do they run?
  6. When we cancel, how do we get our files, and when are your copies destroyed?
  7. What is your breach notification commitment, in hours or days?

A vendor with a hosted archive can have excellent answers to all seven. A vendor that never holds your files gets to skip half the list, which is rather the point.

The Safeguards Rule makes vendor access your job

The FTC Safeguards Rule treats most accounting and tax firms as financial institutions, and its reach does not stop at your own laptops. It requires you to take reasonable steps to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically reassess them. If a vendor’s employees can open your clients’ bank statements and you have never asked how that access is controlled, your written information security program has a hole in it, whether or not anything ever goes wrong.

Vendor-hosted tools can absolutely be run safely under that standard. The rule simply puts the burden of verifying it on you, it recurs, and it grows with how much of your archive the vendor holds. A courier-style tool shrinks the surface you have to keep verifying. For the broader picture of secure collection channels, see secure ways to receive client bank statements.

Where the files live decides who can see them. Vendor-hosted archives generally mean vendor staff can access client documents through support tooling; delivery into storage you control means there is no vendor-side archive to access. Ask every vendor, in writing, who can open a client file and what log proves it.

The skeptical read is the right read

Every vendor in this space, us included, will tell you your data is safe. The useful move is to stop asking “is it safe” and start asking “who can open the file, and what would I see in the log afterward.” Vendors with good answers will give them to you in writing without flinching.

We built StatementFlow around your-own-storage because we had to answer these questions for our own firm first, and the cleanest answer to “who at the vendor can browse the archive” turned out to be: nobody, because there is no archive. If that design matches how you want your clients’ documents handled, we are onboarding firms from the waitlist now through early access.

FAQ

Can software vendors see my clients' bank statements?
It depends on where the software stores them. Tools that keep documents on their own servers usually give support staff a way to open files, ideally logged and policy-bound. Tools that deliver files straight into storage you control, like your firm's own Google Drive, have no archive for staff to browse.
Can StatementFlow staff view the statements it downloads?
No archive of your documents lives on our servers. Each PDF is hash-verified and filed into your firm's own Google Drive, under your permissions and retention rules. We hold encrypted bank connection tokens, job status, and audit logs, which is what our team can see when troubleshooting.
What should I ask a vendor before connecting client bank accounts?
Ask where documents are stored, which employees can view them and under what policy, whether staff access is logged, whether a SOC 2 Type II report exists, who the subprocessors are, and how deletion works when you leave. Get the answers in writing and keep them for your Safeguards file.
Does the FTC Safeguards Rule apply to accounting firms?
Generally yes. Firms that prepare tax returns or handle client financial data are treated as financial institutions under the rule. Among other duties, you must select service providers that can maintain appropriate safeguards, require those safeguards by contract, and periodically reassess them. Vendor document access falls squarely inside that duty.

Keep reading

Chris Wattinger · Technology Lead, Scale CPA. Chris leads technology at Scale CPA and built StatementFlow inside the firm to end the monthly statement chase across its own client book.

Reviewed by Howard Telson, CPA, MST, Partner & Founder at Scale CPA.

LinkedIn · Meet the team behind StatementFlow

Stop chasing. Start closing.

Join the early-access waitlist and be one of the founding firms that never asks a client for a bank statement again.

Get early access