Private by architecture
Security
The private workspace is a separate application with no advertising, session replay, third-party analytics, remote fonts, or file-processing API.
Defensive XML handling
DOCTYPE, ENTITY, XInclude, external-resource constructs, malformed XML, and configured resource-limit violations fail before financial interpretation. Unknown namespaces never fall back to a nearby adapter.
Security claims
CAMT Tools does not claim to verify XML signatures, certificates, bank authenticity, or importer compatibility. Original bytes remain recoverable, and transformed output is labelled synthetic or user-generated as applicable.
Report an issue
Contact security@camttools.com with a synthetic reproduction. Never attach a real bank file or financial value. The machine-readable disclosure policy is available at security.txt.