Who can see your clients' documents? Vendor access, compared
Here is the direct answer: it depends on where the files end up. When a statement-retrieval or document-collection tool stores your clients’ documents on the vendor’s own servers, people who work at that vendor can usually open them. Support tooling exists for a reason, and in a vendor-hosted product, the reason is your files. When the tool delivers documents into storage your firm controls and keeps no copy, there is nothing on the vendor’s side for anyone to browse.
That one architectural choice decides most of what matters for client document privacy. Everything else, the certifications, the access policies, the NDAs, sits on top of it. So before you compare feature lists, ask each vendor a single question: where does the PDF live after you fetch it?
Two places a client statement can live
The vendor’s archive. Most document tools for accountants work this way. The software fetches or receives files, stores them in the vendor’s cloud, and presents them back through the vendor’s app. Hosted tools typically offer conveniences like in-app previews, search, one login for your whole team, and a support desk that can fix a misfiled statement quickly because they can look at the actual file. As hosted products, LedgerSync and LedgerDocs both keep documents on the vendor’s side, and both are established products with years in market.
The costs are just as real. The vendor’s employees are now inside the circle of people who can reach your clients’ financial documents, governed by that vendor’s internal policy rather than yours. Leaving means an export and migration project. And under your security obligations (more on those below), you are now responsible for assessing their staff-access controls, their logging, and their retention, every year, for as long as you use them.
Your own storage. The tool acts as a courier. It fetches the statement, verifies it, drops it into a Drive or SharePoint your firm already controls, and keeps operational metadata rather than documents. Your existing permissions, retention policy, and staff-offboarding checklist keep applying, because the files never left your estate.
The trade-off deserves to be said out loud: a courier-style vendor’s support team cannot pull up your PDF to eyeball a problem. Diagnosis happens from logs and metadata. Slightly slower for a few support cases. Structurally better for privacy.
| Vendor-hosted archive | Your own storage | |
|---|---|---|
| Where the PDF lives | Vendor’s cloud | Your firm’s Drive or SharePoint |
| Who can open it | Your team, plus vendor staff per their policy | Whoever your firm has granted access |
| When you cancel | Export and migration project | Files were always yours |
| Safeguards oversight | You assess their staff-access controls | You assess a delivery pipe |
What public reviews actually say
A named example makes this concrete. LedgerSync is a mature, established statement-retrieval tool for accountants with years in market: 10,000+ banks via Mastercard Open Banking and MX, transaction fetching, check images, and direct pushes into QuickBooks Online, QuickBooks Desktop, Zoho Books, and Accounting CS. Those are genuine strengths, and several of them are things StatementFlow does not do at all.
On the access question, though: reviewers on G2 and Capterra report that LedgerSync support staff can view fetched documents. Nobody is alleging misuse. Hosted archives work this way by design; support can see files because support was built to see files. The question for your firm is whether you knew that, whether your engagement letters and security program account for it, and whether your clients would be comfortable if you explained it to them. We compare the two architectures in more depth in StatementFlow vs LedgerSync.
Two related notes for firms shopping in this category. Hubdoc retired its statement Auto-Fetch feature in early 2022, so it no longer fetches bank statements automatically at all; documents you upload to it live in Hubdoc’s system, integrated with Xero. LedgerDocs treats statement fetching as an add-on to a broader vendor-hosted document management product, which is a sensible design for its purpose but keeps the archive on their side.
How we built StatementFlow
We run an accounting firm. StatementFlow was built inside Scale CPA to fetch statements for our own client book before anyone else’s, which meant we had to answer the vendor-access question for ourselves first. The storage decision came out simple: the firm’s archive should belong to the firm.
The flow: each client connects their bank once through a secure invite link, authenticating at their own bank via Plaid or Mastercard Open Banking. Nobody at the firm and nobody at StatementFlow ever sees credentials. When the bank publishes a statement, we retrieve the official PDF (Plaid documents this in its statements API), verify the download against its SHA-256 hash, and file it into the firm’s own Google Drive, organized by client, year, and month. The same pipeline handles settlement statements from processors like Stripe, PayPal, Square, and Shopify.
What lives on our side: encrypted connection tokens (AES-256-GCM at rest), refresh-job status, the coverage grid, and a full audit log. What does not live on our side: your documents. There is no internal admin screen where someone on our team pages through client statements, because the statements sit in your Drive, behind your permissions.
Two honest caveats.
First, Google still hosts that Drive, under your firm’s Workspace agreement and your admin console. You made that vendor decision long before you met us, and you govern it. StatementFlow declines to become a second archive on top of it.
Second, we are in early access, and we will not wave around certifications we do not have. What we can describe today: bank-side authentication, signature-verified webhooks, role-based access for firm staff, passkey step-up before sensitive actions, and an audit log of who did what and when. The details are on our security page. We are equally plain about scope: no OCR or data extraction (that is Dext, AutoEntry, and DocuClipper territory), no bookkeeping engine, US banks only.
Questions worth asking any vendor
Whichever tool wins your evaluation, get these answered in writing before a single client connects:
- Where exactly are client documents stored, and for how long?
- Which of your employees can view client documents, and under what policy? “Only with permission” is a start; ask what technically enforces it.
- Is every staff access to a client file logged, and can we request that log?
- Do you have a current SOC 2 Type II report? If not, what compensating controls exist, and when is one expected?
- Who are your subprocessors, and where do they run?
- When we cancel, how do we get our files, and when are your copies destroyed?
- What is your breach notification commitment, in hours or days?
A vendor with a hosted archive can have excellent answers to all seven. A vendor that never holds your files gets to skip half the list, which is rather the point.
The Safeguards Rule makes vendor access your job
The FTC Safeguards Rule treats most accounting and tax firms as financial institutions, and its reach does not stop at your own laptops. It requires you to take reasonable steps to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically reassess them. If a vendor’s employees can open your clients’ bank statements and you have never asked how that access is controlled, your written information security program has a hole in it, whether or not anything ever goes wrong.
Vendor-hosted tools can absolutely be run safely under that standard. The rule simply puts the burden of verifying it on you, it recurs, and it grows with how much of your archive the vendor holds. A courier-style tool shrinks the surface you have to keep verifying. For the broader picture of secure collection channels, see secure ways to receive client bank statements.
The skeptical read is the right read
Every vendor in this space, us included, will tell you your data is safe. The useful move is to stop asking “is it safe” and start asking “who can open the file, and what would I see in the log afterward.” Vendors with good answers will give them to you in writing without flinching.
We built StatementFlow around your-own-storage because we had to answer these questions for our own firm first, and the cleanest answer to “who at the vendor can browse the archive” turned out to be: nobody, because there is no archive. If that design matches how you want your clients’ documents handled, we are onboarding firms from the waitlist now through early access.
FAQ
Can software vendors see my clients' bank statements?
Can StatementFlow staff view the statements it downloads?
What should I ask a vendor before connecting client bank accounts?
Does the FTC Safeguards Rule apply to accounting firms?
Keep reading
Chris Wattinger · Technology Lead, Scale CPA. Chris leads technology at Scale CPA and built StatementFlow inside the firm to end the monthly statement chase across its own client book.
Reviewed by Howard Telson, CPA, MST, Partner & Founder at Scale CPA.