SECURITY
Security designed for professional practice work
LEDGEIN uses layered access controls, tenant isolation, auditability and controlled integrations to protect practice and client information. This page describes controls that exist in the product today, and says plainly where something is not yet confirmed.
PRINCIPLES
How security is structured
Identity and access
What someone can see and do follows the role they hold in the practice, and is decided on the server rather than in the browser.
- Role-based permissions for practice users
- Permission checks enforced server-side on every request
- Platform administration is separated from practice user access
- Sessions are managed by the application's authentication layer
Automation and AI boundaries
Automation is deterministic and AI is permission-aware. Neither invents authority the signed-in user does not already have.
- Automation runs configured WHEN / IF / THEN rules, not autonomous agents
- Every automation execution is recorded with its outcome
- Ask LEDGEIN answers only from context the user is already authorised to see
- Consequential actions require explicit human confirmation
- AI does not replace official regulatory sources or deterministic compliance logic
Data isolation
Each practice works in its own tenant. Requests are authorised against the practice the signed-in user belongs to.
- Practice data is logically isolated per tenant
- Authorisation is applied server-side, not assumed from the interface
- Client Portal access is scoped to a single client record
- Cross-tenant access is not available through the product interface
Auditability
Practice work leaves a trail, so a reviewer can see what happened to a job, a document or an obligation.
- Activity on work items, documents and approvals is recorded
- Administrative actions are recorded
- Regulatory review decisions are captured against the update
- Connector activity is visible to the practice
Secure integrations
Connections are authorised by the practice, scoped to that tenant, and can be disconnected at any time.
- Provider credentials and tokens are handled server-side
- Provider secrets are not exposed to browser users
- Each connection belongs to the practice that authorised it
- A practice administrator can disconnect a connection
Practice Server security
The local connector is paired once, holds device credentials, and operates only inside folders the practice approves.
- One-time pairing issues credentials to a specific device
- Only approved folders are available to the connector
- Paths outside approved locations are not reachable
- Credentials can be rotated or revoked from the workspace
Operational security
Changes to the platform are managed centrally, and connector versions are tracked so practices are not left on unknown builds.
- Platform updates are released centrally to all tenants
- Connector version and health are visible in the workspace
- Access to administrative functions is restricted
- Security questions from your review process are answered in writing
IDENTITY AND ACCESS
Access follows the role, and is checked on the server
Practice users
Staff access the practice workspace with the permissions their role carries. Practice administrators manage who has access and what they can do.
Platform administration
Platform administration is a separate access path from practice user access. It is restricted and is not available through ordinary practice accounts.
Client Portal
Portal access is issued for a specific client and is limited to the requests, documents and messages associated with that client.
DATA ISOLATION
One practice, one workspace
Practice boundary
A signed-in user can only reach information belonging to their own practice.
Client boundary
Portal users are limited to the client record their access was issued for.
Connection boundary
An integration authorised by one practice is not available to another.
AUDITABILITY
A traceable record of practice activity
Practice actions
Work items, documents and approvals carry a record of activity against them.
Administrative actions
Changes made through administrative access are recorded.
Regulatory actions
Review decisions on a regulatory update are captured against that update.
Connector actions
Connector activity and status are visible to the practice.
INTEGRATION SECURITY
Connections you authorise, and can withdraw
- Provider authorisation is completed by a practice administrator
- Credentials and tokens are held and used server-side
- Each connection is scoped to the practice that authorised it
- Connections can be disconnected by the practice
LEDGEIN is not affiliated with, endorsed by, or a certified partner of any integration provider named on this website.
PRACTICE SERVER
Local file access, deliberately narrow
- 1
Pairing
A one-time pairing step links the connector to your practice workspace.
- 2
Device credentials
Credentials are issued to that specific device and can be rotated or revoked.
- 3
Approved folders
The practice nominates folders. Paths outside them are not reachable.
- 4
Monitoring
Connector health and version are visible so the practice knows its state.
Technical detail for IT reviewers
The connector runs on a Windows machine you control. Credentials issued during pairing are stored using operating-system credential protection on that machine, and file operations are restricted to the folder paths approved by the practice.
We do not publish transport, endpoint or infrastructure detail here. If your review requires it, contact us and we will handle that discussion directly with your IT team.
DATA HANDLING
What LEDGEIN holds, described plainly
Practice information
Your firm, staff accounts, roles and configuration.
Client information
Client records, entity details and the services they are engaged for.
Documents
Files requested, received and stored through practice workflows.
Communications
Messages exchanged with clients in the context of practice work.
Operational metadata
Tasks, obligations, statuses, timestamps and activity records.
Integration credentials
Tokens for connections you authorise, held server-side.
WHAT WE DO NOT CLAIM
No certification badges you cannot verify
RESPONSIBLE DISCLOSURE
Reporting a potential security issue
How to report
Use our contact form with the Security topic and include enough detail for us to reproduce the issue: what you found, the steps involved, and the impact you believe it has.
We will acknowledge your report and keep you informed while we investigate.
What we ask
- Give us reasonable time to investigate before disclosing publicly.
- Do not access, modify or delete data that is not yours.
- Do not run testing that degrades the service for other practices.
- Do not use social engineering or physical intrusion techniques.
LEDGEIN does not currently run a paid bug bounty programme.
Reviewing LEDGEIN with your IT or risk team?
Send us the questions your review process asks and we will answer them directly, in writing, before you commit to anything.