Security and privacy
LedgerSync is designed to reduce operator risk without making unsupported compliance claims. Tokens stay server-side, access is scoped by organization and client workspace, and operational actions are audited.
What LedgerSync protects
- - OAuth and billing credentials are stored server-side only.
- - Refresh tokens are encrypted before persistence.
- - Webhook signatures are validated before queueing downstream work.
- - Role permissions and client workspace isolation prevent cross-client access.
Operational controls
- - Structured logging with redaction
- - Rate limiting on auth, imports, preview generation, posting, and worker routes
- - Audit log export and scoped data export
- - Retention cleanup for operational payloads and job history
What is not claimed
LedgerSync does not claim SOC 2 certification, HIPAA compliance, guaranteed uptime, or production accounting posting safety beyond what is implemented and documented.
Related articles
Keep moving through setup with the next most relevant guides.
Schedules and webhooks
Understand how auto-sync, webhooks, retries, approvals, and background jobs work together.
Billing and plans
Understand LedgerSync plans, test-mode billing, usage limits, and what happens when you approach a plan threshold.
Troubleshooting common setup and sync issues
Resolve OAuth, shop-domain, realm ID, tenant selection, missing mappings, blocked previews, webhook failures, and worker issues.
LedgerSync FAQ
Quick answers about setup order, sync preview, sandbox posting, billing mode, reviewer access, and operational safety.
Need help? Contact support
Support is the best next step when OAuth, imports, mappings, or reviewer access are blocked.