The part that matters most

Your client's statements never leave this computer.

Not “encrypted in transit.” Not “secure cloud.” Never sent. Here is what that actually means, why it is different from every other tool you have been pitched, and how to verify it without taking our word for anything.

The short version: a calculator, not a fax machine

Most software you have been sold works like a fax machine. You put the document in, it goes down a wire to somebody's office, something happens there, and a result comes back. Their office keeps a copy. That copy is what gets breached, subpoenaed, sold in a bankruptcy, or left on a misconfigured server by a contractor nobody at the vendor has met.

FiduKit works like a calculator on your desk. You put the numbers in, the arithmetic happens right there in front of you, and the answer comes out. Nothing goes down a wire, because there is no wire. When you close the tab, the calculator is empty.

Concretely: your conservatee's bank statements are opened, read, and turned into schedules by code running inside your own browser, on your own computer, using your own processor. The finished packet is written to your own downloads folder. At no point does a statement, a transaction, an account number, or a conservatee's name travel to us.

Prove it yourself in ninety seconds

This is the part competitors cannot copy without rebuilding their product, so we would rather you check than believe us. The walkthrough on the home page shows the check running; here it is step by step, for when you run it on your own accounting. It works in any browser and requires nothing to be installed.

  1. Open FiduKit and get to the upload step, but do not upload yet.
  2. Press F12 (or right-click the page and choose Inspect). A panel opens — that is DevTools, the same panel every web developer uses.
  3. Click the Network tab along the top of that panel. It lists every request the page makes. Click the 🚫 “clear” button so the list is empty.
  4. Now drag in your statement PDFs and let the whole accounting run: parse, categorize, review, balance, preview.
  5. Look back at the Network list. It is still empty. Not "a few small requests" — empty. Nothing was sent, so nothing appears.

If you would like your IT-literate colleague to be the one who checks, hand them this paragraph: the processing path is pure client-side JavaScript with a Web Worker; there is no fetch to any origin during the file-select→preview span; the Content-Security-Policy served with the app restricts connect-src to our own origin plus the checkout provider, so even a compromised dependency has nowhere to send data; and the zero-network property is asserted by an automated test that fails the build if a single request appears in that window.

What we do hold — the honest list

"Nothing leaves your computer" is a claim about your client's financial data, and it is exact. It is not a claim that we know nothing about you. Here is everything on our servers:

We holdWhy
Your email addressSo you can sign in and so we can email deadline reminders.
Case metadata: a case label and an accounting due dateSo the reminder says which accounting is due. A label like "Alvarez, second accounting" — not the statements behind it.
The fact that you purchasedSo the download stays unlocked on your other computer.
Standard web server logsRequest metadata only, by architecture — they never see statement data because statement data never reaches a server.

That is the complete list. No statements, no transactions, no balances, no account numbers, no conservatee names, no documents. The full retention schedule is in the privacy policy.

No analytics inside the app. At all.

Plenty of "privacy-first" products send anonymized usage events. We send none — no counters, no crash pings, no opt-in checkbox that lets us claim consent later. The app's outbound network traffic during an accounting is zero, and it is zero because that is the only version of the claim that survives someone opening DevTools.

This marketing site is a separate matter and we will be equally plain about it: it uses Cloudflare Web Analytics, which counts page views without cookies and without tracking you across sites. This site sets no cookies of any kind.

No AI touches your client's finances

There is no AI anywhere in the data path, and that is a permanent architectural decision rather than a current-version caveat. Categorization is deterministic rule-based code with a published logic you can inspect in the review queue — every flag states its reason. Your conservatee's spending does not train a model, does not transit a vendor API, and does not get "processed" by anything that could be subpoenaed later.

What if FiduKit disappears?

Then your files still work. Your accounting lives in your browser's local storage and in the encrypted project file you can export at any time; your packet is a PDF in your downloads folder; your working papers are a CSV. Nothing is trapped behind a login that has to keep existing. Software that holds your work hostage is a business model, not a feature.

Reporting a security issue

Email [email protected]. We read it, we answer, and we will not threaten a researcher who tells us something true. Please do not include client data in a report — a description of the behaviour is always enough.

Verify it before you trust it.

The walkthrough shows the Network tab staying empty while a real accounting runs, and after you buy you can run the same check on your own statements. The Network tab is the whole argument.

If we can't read your statements well enough to build the accounting, tell us and we refund it — no argument, no forms.