Security

The people who lose sleep about your client data.

You hold Social Security numbers, bank details and the whole financial life of every client you have. If any of it walks, it is your name on the letter and your clients reading about it. This page is what we do about that, in enough detail that you can judge it rather than take our word for it.

01

Encryption, everywhere

All data is encrypted in transit (TLS) and at rest. That covers your client records, documents, messages, and e-signature envelopes — everything your firm stores in LedgerOS.

02

Isolation enforced at the database itself

Every record in LedgerOS belongs to exactly one firm, and that boundary is enforced by row-level security inside the database — not just by application code. A request from one firm’s session structurally cannot read another firm’s data, even in the event of an application bug.

Client portal accounts live behind a separate, hard authentication boundary from firm accounts.

03

Identity verification on signatures

E-signature requests for returns support knowledge-based authentication (KBA) — the same IRS-recognized identity verification standard used for Form 8879 across the industry. Signature events are recorded with a full audit trail.

04

Access on your terms

Your team’s access is role-based, and you control what clients see folder-by-folder. Sessions are bound to the portal they belong to: a client signing in on one firm’s portal cannot carry that session anywhere else.

05

Your data is yours

Your client records, documents, and history belong to your firm. You can export your data, and if you ever leave, it leaves with you. We don’t sell data, and we don’t show ads.

06

Infrastructure

LedgerOS runs on enterprise cloud infrastructure from providers that maintain their own independent security certifications, with encrypted backups and continuous monitoring, including automated error and anomaly detection.

What’s next

SOC 2 Type II is on the roadmap, not in the drawer. We have not been audited yet, and we would rather tell you here than have you assume otherwise and find out during diligence. The report goes on this page the day we have it.

Ask us anything

If your firm uses a vendor security questionnaire, send it over — the founder completes these personally. Write us at the address in your LedgerOS account, or from this site’s contact options.

Your data, and getting it back

The questions your own clients will ask you, answered by what the product does rather than by what we promise.

Export, at any time
Documents export as an archive with a manifest, and the manifest accounts for every file you selected — inside the archive, or listed with the reason it is not. There is no path that quietly drops a document from an export and still reports success.
Retention you set, per folder
Folder templates carry a retention period, so a client’s tax returns and their correspondence do not have to be kept for the same number of years. Documents reaching the end of their period surface for review rather than disappearing.
Legal holds override deletion
A client under litigation or examination can be placed on hold, and a hold outranks retention: nothing under it is removed by a schedule while the hold stands.
An audit log that includes us
Every consequential action is recorded with who did it — and “who” distinguishes a member of your firm, a client in the portal, an automation, the AI, and LedgerOS support. If we look at something in your account, that is a row you can read.

Subprocessors

Every third party that can hold or process your firm’s data, and what each one can see. Last checked against the application on 20 August 2026.

LedgerOS subprocessors, their purpose, and the data each can access
VendorPurposeWhat it can see
SupabaseDatabase, authentication and document storageAll firm and client records, and every stored document
VercelApplication hosting and deliveryRequests in transit; no application data at rest
AnthropicDocument classification, tax research and reasonable-comp draftingThe contents of a document being classified, and the text of a research question. Under Anthropic’s commercial API terms these inputs are not used to train their models.
StripeClient payments and LedgerOS subscription billingPayer name, amount and payment method. Card details are entered with the processor and are never held by LedgerOS.
AffiniPay (CPACharge)Only if connectedClient payments, as an alternative gatewayPayer name, amount and payment method
NylasOnly if connectedEmail and calendar connectionMessages and events in the mailbox or calendar you connect
MailgunTransactional email — invoices, notifications, export linksRecipient address and message contents
SentryError monitoringDiagnostic data about failures; not a data store for firm records
IntercomSupport conversationsWhat you write to support, and your contact details
EntriOnly if connectedGuided DNS setup for a sending domain or portal domainThe DNS records for the domain you are configuring

A firm connects one payment gateway, not both. Anything marked “only if connected” never sees your data unless you set it up.

Found something?

Report it to support@tryledgeros.com and it reaches the people who can fix it. We will confirm we have it, tell you what we found, and tell you when it is closed.

We do not run a paid bounty program yet and will not pretend otherwise — but we have never argued with someone who brought us a real problem. Other ways to reach us →

Ready to retire the stack?

One plan for the whole practice — $129 per seat, every Practice module included. Start your free trial today; migration support from your current tools comes standard.

14-day free trial · No credit card required · Cancel anytime