New: Shopify and Stripe reconciliation workflows are now in betaJoin beta now
DocsOperationsSecurity and privacy
OperationsLast updated June 4, 2026

Security and privacy

LedgerSync is designed to reduce operator risk without making unsupported compliance claims. Tokens stay server-side, access is scoped by organization and client workspace, and operational actions are audited.

What LedgerSync protects

  • - OAuth and billing credentials are stored server-side only.
  • - Refresh tokens are encrypted before persistence.
  • - Webhook signatures are validated before queueing downstream work.
  • - Role permissions and client workspace isolation prevent cross-client access.

Operational controls

  • - Structured logging with redaction
  • - Rate limiting on auth, imports, preview generation, posting, and worker routes
  • - Audit log export and scoped data export
  • - Retention cleanup for operational payloads and job history

What is not claimed

LedgerSync does not claim SOC 2 certification, HIPAA compliance, guaranteed uptime, or production accounting posting safety beyond what is implemented and documented.

Need help? Contact support

Support is the best next step when OAuth, imports, mappings, or reviewer access are blocked.