Legal
Security & Compliance
Last updated 1 August 2026
Financial records deserve database-level protection, not interface-level checks. This page summarises how we protect your workspace.
Tenant isolation
Every table carrying company data is protected by row-level security policies keyed to your membership. A query issued for one company can never return another company's rows, regardless of application code.
Immutable ledger
Database triggers reject updates and deletes on posted journal entries, journal lines and audit logs. Corrections are recorded as reversing entries.
Access control
Roles range from owner and accountant through to auditor and contractor. Payroll data is gated behind a dedicated permission check evaluated in the database.
Authentication
Email and password with breach-list checking, Google sign-in, and SAML 2.0 single sign-on for enterprise customers using Okta, Entra ID, OneLogin or any compliant identity provider.
Encryption
All traffic is served over TLS 1.2 or higher. Data at rest is encrypted with AES-256. Secrets are stored in a managed vault and never in application code.
Monitoring and response
Administrative actions are logged immutably. We investigate suspected incidents immediately and notify affected customers without undue delay.
Responsible disclosure
Report vulnerabilities to security@ledger.example. We acknowledge reports within two business days and do not pursue researchers acting in good faith.
Questions about this document? Email legal@ledger.example.