The people who lose sleep about your client data.
You hold Social Security numbers, bank details and the whole financial life of every client you have. If any of it walks, it is your name on the letter and your clients reading about it. This page is what we do about that, in enough detail that you can judge it rather than take our word for it.
Encryption, everywhere
All data is encrypted in transit (TLS) and at rest. That covers your client records, documents, messages, and e-signature envelopes — everything your firm stores in LedgerOS.
Isolation enforced at the database itself
Every record in LedgerOS belongs to exactly one firm, and that boundary is enforced by row-level security inside the database — not just by application code. A request from one firm’s session structurally cannot read another firm’s data, even in the event of an application bug.
Client portal accounts live behind a separate, hard authentication boundary from firm accounts.
Identity verification on signatures
E-signature requests for returns support knowledge-based authentication (KBA) — the same IRS-recognized identity verification standard used for Form 8879 across the industry. Signature events are recorded with a full audit trail.
Access on your terms
Your team’s access is role-based, and you control what clients see folder-by-folder. Sessions are bound to the portal they belong to: a client signing in on one firm’s portal cannot carry that session anywhere else.
Your data is yours
Your client records, documents, and history belong to your firm. You can export your data, and if you ever leave, it leaves with you. We don’t sell data, and we don’t show ads.
Infrastructure
LedgerOS runs on enterprise cloud infrastructure from providers that maintain their own independent security certifications, with encrypted backups and continuous monitoring, including automated error and anomaly detection.
What’s next
SOC 2 Type II is on the roadmap, not in the drawer. We have not been audited yet, and we would rather tell you here than have you assume otherwise and find out during diligence. The report goes on this page the day we have it.
Ask us anything
If your firm uses a vendor security questionnaire, send it over — the founder completes these personally. Write us at the address in your LedgerOS account, or from this site’s contact options.
Your data, and getting it back
The questions your own clients will ask you, answered by what the product does rather than by what we promise.
- Export, at any time
- Documents export as an archive with a manifest, and the manifest accounts for every file you selected — inside the archive, or listed with the reason it is not. There is no path that quietly drops a document from an export and still reports success.
- Retention you set, per folder
- Folder templates carry a retention period, so a client’s tax returns and their correspondence do not have to be kept for the same number of years. Documents reaching the end of their period surface for review rather than disappearing.
- Legal holds override deletion
- A client under litigation or examination can be placed on hold, and a hold outranks retention: nothing under it is removed by a schedule while the hold stands.
- An audit log that includes us
- Every consequential action is recorded with who did it — and “who” distinguishes a member of your firm, a client in the portal, an automation, the AI, and LedgerOS support. If we look at something in your account, that is a row you can read.
Subprocessors
Every third party that can hold or process your firm’s data, and what each one can see. Last checked against the application on 20 August 2026.
| Vendor | Purpose | What it can see |
|---|---|---|
| Supabase | Database, authentication and document storage | All firm and client records, and every stored document |
| Vercel | Application hosting and delivery | Requests in transit; no application data at rest |
| Anthropic | Document classification, tax research and reasonable-comp drafting | The contents of a document being classified, and the text of a research question. Under Anthropic’s commercial API terms these inputs are not used to train their models. |
| Stripe | Client payments and LedgerOS subscription billing | Payer name, amount and payment method. Card details are entered with the processor and are never held by LedgerOS. |
| AffiniPay (CPACharge)Only if connected | Client payments, as an alternative gateway | Payer name, amount and payment method |
| NylasOnly if connected | Email and calendar connection | Messages and events in the mailbox or calendar you connect |
| Mailgun | Transactional email — invoices, notifications, export links | Recipient address and message contents |
| Sentry | Error monitoring | Diagnostic data about failures; not a data store for firm records |
| Intercom | Support conversations | What you write to support, and your contact details |
| EntriOnly if connected | Guided DNS setup for a sending domain or portal domain | The DNS records for the domain you are configuring |
A firm connects one payment gateway, not both. Anything marked “only if connected” never sees your data unless you set it up.
Found something?
Report it to support@tryledgeros.com and it reaches the people who can fix it. We will confirm we have it, tell you what we found, and tell you when it is closed.
We do not run a paid bounty program yet and will not pretend otherwise — but we have never argued with someone who brought us a real problem. Other ways to reach us →
Ready to retire the stack?
One plan for the whole practice — $129 per seat, every Practice module included. Start your free trial today; migration support from your current tools comes standard.
14-day free trial · No credit card required · Cancel anytime