Security at LedgerLine
Contracts, site plans, and budgets are some of the most sensitive documents on a project. Here's how we protect them — and how the system is built so people only ever see what they should.
All traffic to LedgerLine is served over HTTPS/TLS, and your data and uploaded files are encrypted at rest by our infrastructure providers. Backups are additionally encrypted with a key we control before they leave our systems.
Every project is governed by role-based permissions enforced at the database level (row-level security), not just in the app. Builders see their portfolio; general contractors and subcontractors see only the projects they've been invited to, scoped to what their role should see.
Accounts support two-factor authentication (2FA) for a second layer of login security. Repeated failed sign-in attempts are automatically rate-limited to slow down credential-guessing.
Uploaded documents are checked against their actual file contents — not just their extension or declared type — before they're stored, and there's a per-file size limit. Only expected document types (PDFs, images, and common office formats) are accepted.
Your database and uploaded files are backed up every night to encrypted, independent off-site storage kept separate from the primary system. We regularly test that those backups actually restore, so recovery isn't a guess.
We never see or store your full card number. All billing runs through Stripe, a PCI-DSS Level 1 certified payment processor; card data goes directly to Stripe and never touches our servers.
Infrastructure & subprocessors
LedgerLine runs on established infrastructure providers. We share the current list so you always know who processes your data on our behalf.
Reporting a vulnerability
If you believe you've found a security issue, please email support@ledgerlinere.com with the details. We take reports seriously and will respond as quickly as we can.
See also our Privacy Policy for how we collect, use, and retain data.