ledgerhands.
Security

Built for firms that answer to their clients

Your clients trust you with their financials. We're the layer that has to be worthy of that trust — so security is designed into every placement, not added after.

Photo — secure workstation

What's in place today

  • NDAs & confidentiality

    Every professional signs NDAs and confidentiality agreements before any client access — covering your firm and your clients.

  • Multi-factor authentication

    MFA/TOTP enforced on every internal admin and staff account, verified at onboarding. Client portal access uses single-use, time-limited sign-in links instead of passwords — nothing to phish or leak.

  • Secure managed workstations

    Company-issued, monitored machines with no local data storage — client data never lives on a personal device.

  • Role-based access

    Least-privilege by default: each professional can reach only the systems and clients their role requires.

  • Password management

    Enterprise password vault across the team — no shared logins, no credentials in spreadsheets.

  • Encrypted systems

    Encryption in transit and at rest across our stack, with access logging on sensitive systems.

Where we're headed

SOC 2 roadmap

  • NOW

    Controls above enforced on every placement; policies documented.

  • NEXT

    Continuous monitoring platform and formal readiness assessment.

  • AT SCALE

    SOC 2 Type II audit as the client base grows.

Have a security questionnaire?

Send it over — we'll complete it before your discovery call.

Book a discovery call