Skip to content

SECURITY

Security designed for professional practice work

LEDGEIN uses layered access controls, tenant isolation, auditability and controlled integrations to protect practice and client information. This page describes controls that exist in the product today, and says plainly where something is not yet confirmed.

PRINCIPLES

How security is structured

Practice and client information carries professional obligations. These are the areas your IT or risk reviewer is most likely to ask about.
  • Identity and access

    What someone can see and do follows the role they hold in the practice, and is decided on the server rather than in the browser.

    • Role-based permissions for practice users
    • Permission checks enforced server-side on every request
    • Platform administration is separated from practice user access
    • Sessions are managed by the application's authentication layer
  • Automation and AI boundaries

    Automation is deterministic and AI is permission-aware. Neither invents authority the signed-in user does not already have.

    • Automation runs configured WHEN / IF / THEN rules, not autonomous agents
    • Every automation execution is recorded with its outcome
    • Ask LEDGEIN answers only from context the user is already authorised to see
    • Consequential actions require explicit human confirmation
    • AI does not replace official regulatory sources or deterministic compliance logic
  • Data isolation

    Each practice works in its own tenant. Requests are authorised against the practice the signed-in user belongs to.

    • Practice data is logically isolated per tenant
    • Authorisation is applied server-side, not assumed from the interface
    • Client Portal access is scoped to a single client record
    • Cross-tenant access is not available through the product interface
  • Auditability

    Practice work leaves a trail, so a reviewer can see what happened to a job, a document or an obligation.

    • Activity on work items, documents and approvals is recorded
    • Administrative actions are recorded
    • Regulatory review decisions are captured against the update
    • Connector activity is visible to the practice
  • Secure integrations

    Connections are authorised by the practice, scoped to that tenant, and can be disconnected at any time.

    • Provider credentials and tokens are handled server-side
    • Provider secrets are not exposed to browser users
    • Each connection belongs to the practice that authorised it
    • A practice administrator can disconnect a connection
  • Practice Server security

    The local connector is paired once, holds device credentials, and operates only inside folders the practice approves.

    • One-time pairing issues credentials to a specific device
    • Only approved folders are available to the connector
    • Paths outside approved locations are not reachable
    • Credentials can be rotated or revoked from the workspace
  • Operational security

    Changes to the platform are managed centrally, and connector versions are tracked so practices are not left on unknown builds.

    • Platform updates are released centrally to all tenants
    • Connector version and health are visible in the workspace
    • Access to administrative functions is restricted
    • Security questions from your review process are answered in writing

IDENTITY AND ACCESS

Access follows the role, and is checked on the server

Interface elements are not the security boundary. Every request is authorised against the signed-in user, their practice and their role before data is returned.

Practice users

Staff access the practice workspace with the permissions their role carries. Practice administrators manage who has access and what they can do.

Platform administration

Platform administration is a separate access path from practice user access. It is restricted and is not available through ordinary practice accounts.

Client Portal

Portal access is issued for a specific client and is limited to the requests, documents and messages associated with that client.

Multi-factor authentication. We do not claim multi-factor authentication as a confirmed, generally available control on this website. If MFA is a requirement for your practice, please ask us and we will confirm the current position in writing before you commit.

DATA ISOLATION

One practice, one workspace

Each practice's information is logically isolated from every other practice. Authorisation happens server-side, so the separation does not depend on what the interface chooses to display.

Practice boundary

A signed-in user can only reach information belonging to their own practice.

Client boundary

Portal users are limited to the client record their access was issued for.

Connection boundary

An integration authorised by one practice is not available to another.

AUDITABILITY

A traceable record of practice activity

Practices are regularly asked to show how something was handled. LEDGEIN records activity across the areas below so that question can be answered from the workspace.
  • Practice actions

    Work items, documents and approvals carry a record of activity against them.

  • Administrative actions

    Changes made through administrative access are recorded.

  • Regulatory actions

    Review decisions on a regulatory update are captured against that update.

  • Connector actions

    Connector activity and status are visible to the practice.

Audit coverage reflects current product capability. We do not claim that every action in every part of the system is recorded permanently or is exportable as a formal audit report. If your review requires specific audit evidence, ask us what is available today.

INTEGRATION SECURITY

Connections you authorise, and can withdraw

Integrations are connected by a practice administrator through the provider's own authorisation flow. Credentials stay on the server.
  • Provider authorisation is completed by a practice administrator
  • Credentials and tokens are held and used server-side
  • Each connection is scoped to the practice that authorised it
  • Connections can be disconnected by the practice

LEDGEIN is not affiliated with, endorsed by, or a certified partner of any integration provider named on this website.

PRACTICE SERVER

Local file access, deliberately narrow

The LEDGEIN Practice Server lets approved folders on a machine in your office take part in document workflows. Its access is explicit and revocable.
  1. 1

    Pairing

    A one-time pairing step links the connector to your practice workspace.

  2. 2

    Device credentials

    Credentials are issued to that specific device and can be rotated or revoked.

  3. 3

    Approved folders

    The practice nominates folders. Paths outside them are not reachable.

  4. 4

    Monitoring

    Connector health and version are visible so the practice knows its state.

Technical detail for IT reviewers

The connector runs on a Windows machine you control. Credentials issued during pairing are stored using operating-system credential protection on that machine, and file operations are restricted to the folder paths approved by the practice.

We do not publish transport, endpoint or infrastructure detail here. If your review requires it, contact us and we will handle that discussion directly with your IT team.

DATA HANDLING

What LEDGEIN holds, described plainly

Understanding the categories of information involved is usually more useful to a reviewer than a list of technologies.
  • Practice information

    Your firm, staff accounts, roles and configuration.

  • Client information

    Client records, entity details and the services they are engaged for.

  • Documents

    Files requested, received and stored through practice workflows.

  • Communications

    Messages exchanged with clients in the context of practice work.

  • Operational metadata

    Tasks, obligations, statuses, timestamps and activity records.

  • Integration credentials

    Tokens for connections you authorise, held server-side.

Encryption. LEDGEIN is delivered over HTTPS, so traffic between your browser and the service is encrypted in transit. We do not publish claims about storage-level encryption, key management or backup architecture on this page until each is confirmed by our infrastructure review. We deliberately avoid marketing terms such as "bank-grade" or "military-grade".
Retention, residency and recovery. We do not state specific retention periods, a data residency location, or backup and recovery objectives on this page. These are being finalised, and we would rather say nothing than state something we cannot stand behind. Ask us and we will share the current position.

WHAT WE DO NOT CLAIM

No certification badges you cannot verify

Trust pages are easy to inflate. These are the claims LEDGEIN does not make.
LEDGEIN does not hold, and does not claim, SOC 2, ISO 27001, PCI DSS or any government security certification. Where payment processing is handled by a third-party provider, that provider's own compliance does not transfer to LEDGEIN.
LEDGEIN does not claim guaranteed compliance, zero downtime, or that any system is 100% secure. LEDGEIN is software that supports professional work — it does not provide accounting, tax, legal or financial advice.

RESPONSIBLE DISCLOSURE

Reporting a potential security issue

If you believe you have found a vulnerability in LEDGEIN, we would like to hear from you before it is shared publicly.

How to report

Use our contact form with the Security topic and include enough detail for us to reproduce the issue: what you found, the steps involved, and the impact you believe it has.

We will acknowledge your report and keep you informed while we investigate.

What we ask

  • Give us reasonable time to investigate before disclosing publicly.
  • Do not access, modify or delete data that is not yours.
  • Do not run testing that degrades the service for other practices.
  • Do not use social engineering or physical intrusion techniques.

LEDGEIN does not currently run a paid bug bounty programme.

Reviewing LEDGEIN with your IT or risk team?

Send us the questions your review process asks and we will answer them directly, in writing, before you commit to anything.