Built to be trusted

Security at LedgerLine

Contracts, site plans, and budgets are some of the most sensitive documents on a project. Here's how we protect them — and how the system is built so people only ever see what they should.

Encryption in transit and at rest

All traffic to LedgerLine is served over HTTPS/TLS, and your data and uploaded files are encrypted at rest by our infrastructure providers. Backups are additionally encrypted with a key we control before they leave our systems.

Access on a need-to-know basis

Every project is governed by role-based permissions enforced at the database level (row-level security), not just in the app. Builders see their portfolio; general contractors and subcontractors see only the projects they've been invited to, scoped to what their role should see.

Authentication and sign-in protection

Accounts support two-factor authentication (2FA) for a second layer of login security. Repeated failed sign-in attempts are automatically rate-limited to slow down credential-guessing.

Upload validation

Uploaded documents are checked against their actual file contents — not just their extension or declared type — before they're stored, and there's a per-file size limit. Only expected document types (PDFs, images, and common office formats) are accepted.

Nightly off-site backups and tested recovery

Your database and uploaded files are backed up every night to encrypted, independent off-site storage kept separate from the primary system. We regularly test that those backups actually restore, so recovery isn't a guess.

Payments handled by Stripe

We never see or store your full card number. All billing runs through Stripe, a PCI-DSS Level 1 certified payment processor; card data goes directly to Stripe and never touches our servers.

Infrastructure & subprocessors

LedgerLine runs on established infrastructure providers. We share the current list so you always know who processes your data on our behalf.

SupabaseDatabase, authentication, and file storage
VercelApplication hosting and delivery
Backblaze B2Encrypted off-site backup storage
StripeSubscription billing and payments
ResendTransactional email (invites, password resets)
GitHubSource code and automated backup workflows
AnthropicAI assistant (processes only what you send it; not used to train models)

Reporting a vulnerability

If you believe you've found a security issue, please email support@ledgerlinere.com with the details. We take reports seriously and will respond as quickly as we can.

See also our Privacy Policy for how we collect, use, and retain data.