Back to the registry
Agent passport

Financial Data Extraction Platform

Business Compass LLC · Finance & Accounting

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownContainer
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Financial Data Extraction Platform turns scanned and digital bank statement PDFs into structured, reconcilable transaction data - without sending sensitive financial records to a third-party processor. The full stack (web app, AppSync GraphQL API, Cognito user pool, DynamoDB tables, Lambda pipeline, S3 buckets) deploys into your own AWS account via a single CloudFormation stack, so all data and access logs stay within your VPC, region, and IAM boundary.

Pipeline. Upload a multi-page PDF; Amazon Textract is invoked asynchronously with TABLES + FORMS + QUERIES. Handwriting and signature density are scored automatically and statements above the threshold are quarantined to a separate KMS-encrypted bucket for review. Successful extractions populate a transaction table with per-row bounding boxes for the side-by-side reviewer, plus header metadata (account number, holder, period, starting/ending balances). A reconciler validates the running balance against the extracted total and flags the document if the delta exceeds tolerance.

Show the rest of the publisher’s description (3 more lines)

Review and export. Reviewers correct individual rows with full audit-trail capture; admins build XLSX/CSV export templates with column ordering, filters, and granularity choice (transaction- or document-level). Recurring exports run on cron and deliver to operators via SES email or a presigned-link download. CSV and XLSX writers neutralize formula-injection payloads (=, +, -, @ prefixes).

Compliance posture. Cognito enforces TOTP MFA and a Pre-Token-Generation v2 trigger writes an organizationId claim into both the access and ID tokens so AppSync's owner-field rules give every request strict per-tenant data isolation. S3 buckets use customer-managed KMS, Object Lock (7-year retention floor), bucket-key acceleration, and a deny-insecure-transport policy. GuardDuty Malware Protection scans every upload before it enters the extraction pipeline. CloudTrail data events on every storage bucket and a dedicated audit DynamoDB table record every state-changing action with the caller's sub, role, and IP.

Operations. Single-stack CloudFormation template - bring your own VPC or let the stack create one. ECS Fargate behind ALB with horizontal autoscaling. Optional HTTPS listener gated by a CertificateArn parameter. No proprietary runtime: every component is a standard AWS service.

Highlights

Highlighted by the publisher on AWS Marketplace.

Stays in your account. Single-stack deployment into your AWS region - your PDFs never leave your VPC, your KMS keys, or your IAM boundary.

Audit-ready by default. Cognito MFA, per-tenant token claims, Object Lock retention, GuardDuty malware scanning, and a tamper-evident audit log on every action.

From PDF to export in minutes. Async Textract pipeline auto-extracts transactions with bounding boxes, reconciles against statement balances, and emails recurring XLSX/CSV exports.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

1 listed
Plan
$9,000.00
MONTHLY

Refund terms

As stated by the publisher on AWS Marketplace.

temp

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
Container
Need help? Schedule a support session with our team and we'll get you sorted. https://businesscompassllc.com/schedule-appointment
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.