Skip to content

Security questionnaire

Answers to the categories a security reviewer or a CAIQ-style questionnaire asks about; the page follows those categories only and is not a completed standard assessment. Where a value depends on a business decision that has not been confirmed yet, the answer says so plainly instead of guessing; the trust page in the app is where confirmed values are published.

Hosting

Where does Ledger run, and where is customer data stored? The hosting provider and region are not yet confirmed on this page. The confirmed provider and region will be published on the trust page; see subprocessors for the current list.

Is the database managed or self-hosted? Not yet confirmed. The database provider will be published on the trust page once it has been confirmed.

Encryption

How is data encrypted at rest? Every stored connection credential is envelope-encrypted per customer: a fresh random data key is generated for each encryption, used once to encrypt the credential, and then discarded. Only a copy of that data key wrapped by a key held in the managed key store is kept alongside the encrypted credential. The plaintext data key is never cached or logged.

Is the encryption bound to a specific customer? Yes. Data keys are per customer. Each one is wrapped by a key in the managed key store, and that use of the key is bound to the customer's identifier through authenticated context, so decrypting with a different customer's identifier fails. The key-store key that wraps the data keys is itself separately access-controlled.

How is data encrypted in transit? Ledger is served over HTTPS. This page does not make claims about the encryption of traffic between internal services beyond that.

How are credentials rotated? Rotating a connection's credentials re-encrypts them with a new data key and replaces the old encrypted copy.

Access control

How do customers authenticate? Through a hosted authentication service (WorkOS; see subprocessors). Ledger does not keep its own username and password store.

How is tenant isolation enforced? Every request a signed-in user makes is limited to that user's own customer account. Reading another customer's resource by id returns "not found", never a "forbidden" that would confirm the resource exists.

Is there an audit trail of user actions? Yes. Actions a signed-in user takes that change data in Ledger are recorded in an audit log entry saying who did it, what the action was, and when. See the audit log page for what an entry does and does not capture and for the current state of retention.

Software development and dependencies

Are dependencies checked for known vulnerabilities? Ledger's server-side dependencies are checked for known vulnerabilities as part of its automated checks before changes are released. This page makes no broader claim about other scanning.

Incident response

What is the breach notification commitment? Ledger has not yet published a breach-notification window. Any window will appear on the trust page once it has been confirmed; none is promised here.

Subprocessors

See subprocessors.md for the full, current list.

Data retention

See data retention for what is retained, why, and how deletion works. No deletion deadline is published yet.