Private by architecture

Security

The private workspace is a separate application with no advertising, session replay, third-party analytics, remote fonts, or file-processing API.

Defensive XML handling

DOCTYPE, ENTITY, XInclude, external-resource constructs, malformed XML, and configured resource-limit violations fail before financial interpretation. Unknown namespaces never fall back to a nearby adapter.

Security claims

CAMT Tools does not claim to verify XML signatures, certificates, bank authenticity, or importer compatibility. Original bytes remain recoverable, and transformed output is labelled synthetic or user-generated as applicable.

Report an issue

Contact security@camttools.com with a synthetic reproduction. Never attach a real bank file or financial value. The machine-readable disclosure policy is available at security.txt.