New25% off Growth · 30% off EnterpriseClaim

Legal

Security & Compliance

Last updated 1 August 2026

Financial records deserve database-level protection, not interface-level checks. This page summarises how we protect your workspace.

Tenant isolation

Every table carrying company data is protected by row-level security policies keyed to your membership. A query issued for one company can never return another company's rows, regardless of application code.

Immutable ledger

Database triggers reject updates and deletes on posted journal entries, journal lines and audit logs. Corrections are recorded as reversing entries.

Access control

Roles range from owner and accountant through to auditor and contractor. Payroll data is gated behind a dedicated permission check evaluated in the database.

Authentication

Email and password with breach-list checking, Google sign-in, and SAML 2.0 single sign-on for enterprise customers using Okta, Entra ID, OneLogin or any compliant identity provider.

Encryption

All traffic is served over TLS 1.2 or higher. Data at rest is encrypted with AES-256. Secrets are stored in a managed vault and never in application code.

Monitoring and response

Administrative actions are logged immutably. We investigate suspected incidents immediately and notify affected customers without undue delay.

Responsible disclosure

Report vulnerabilities to security@ledger.example. We acknowledge reports within two business days and do not pursue researchers acting in good faith.

Questions about this document? Email legal@ledger.example.