SOC 2
In progressControl environment under formalization. Targeting SOC 2 Type I, then Type II, as Ledgera pursues institutional customers.
Security & Trust
Ledgera is the financial and operational infrastructure layer for service and industrial companies. That role only works if institutions trust how we handle their data. This page states - without marketing language - how we secure it today and what we are building toward.
Control environment under formalization. Targeting SOC 2 Type I, then Type II, as Ledgera pursues institutional customers.
Roadmapped after SOC 2 Type II. Reuses the same control set to reduce effort.
TLS 1.2+ everywhere: customer traffic, API traffic, and database connections.
Provider-level disk encryption plus AES-256-GCM application-layer encryption for integration credentials and tokens.
Cross-tenant path and body access enforced in middleware and covered by automated tests.
Sensitive route access is logged per user, method, path, and company. Backups are encrypted and restore-tested.
Customer data is processed on US-hosted infrastructure. Systems of record (ServiceTitan, QuickBooks, banks, payroll) stay at the customer. Ledgera connects to them over authenticated, encrypted integrations.
Customer
Browser / API clients
Vercel + Supabase Edge
TLS · CDN · Auth
Railway API
Express · rate limits · tenant isolation
Encrypted PostgreSQL
US region · encrypted backups
These controls are implemented in the platform today and are subject to automated tests and CI scanning.
Ledgera does not claim certifications it does not hold. This is the path to institutional-grade compliance, each stage triggered by real customer requirements rather than speculative spending.
Tenant isolation, encryption, rate limiting, audit logs, tested backups, secret scanning, and this Trust Center.
Close gaps exposed by real security questionnaires. Formalize access reviews, staging parity, and control narratives.
Continuous evidence collection via a compliance platform, independent auditor, annual penetration test, and workforce SSO.
Regional data architectures (US/EU/CA), customer SSO, and advanced governance as institutional customers require.
Security is not a snapshot - it is a compounding record of controls shipped, policies published, and audits passed. This timeline is append-only: every milestone is dated and retained, so you can see how Ledgera's program has improved over months, years, and decades - and hold us to it.
Published six auditable procedures - access control, change management, vulnerability management, encryption & key management, data retention & deletion, and security monitoring - converting code-level controls into evidence-producing operations.
Added repository-level protections that block credential files from ever being committed, closing a high-severity finding from the August security audit.
Deployed secret scanning in CI (gitleaks) and npm audit gates, plus pre-commit and pre-push hooks, so every push is scanned for credentials and vulnerable dependencies.
Removed the duplicate global rate limiter and cleaned duplicated CI steps. A single enforced rate-limit posture (100 requests/15 min global, 10/15 min webhooks) is now in effect.
Published severity-classified incident response: SEV0-SEV3 definitions, containment and recovery phases, customer notification obligations, and a quarterly tabletop checklist.
Documented every data class, its sensitivity and retention, all US-region storage locations, integration data flows, subprocessors, key inventory, and logs.
Published the codebase-audited roadmap to institutional trust: tenant isolation, JWKS auth, AES-256-GCM credential encryption, tested backups, and a phased path to SOC 2 and ISO 27001.
Q4 2026
First formal quarterly reviews
Access, vulnerability, and retention reviews with incident response tabletop.
H1 2027
SOC 2 readiness assessment
Control narrative draft and gap analysis with an independent auditor.
2027+
SOC 2 Type I, then Type II
Independent examination after controls operate for 3-6 months.
Future
ISO 27001 & data residency
Regions, customer SSO, and advanced governance as customers require.
We share customer data only with subprocessors required to operate the service. We do not sell customer data. A full data processing agreement is available on request.
| Subprocessor | Role | Region |
|---|---|---|
| Vercel | Frontend hosting & edge delivery | US / Global edge |
| Railway | Backend hosting (US region) | US |
| Supabase | Authentication & PostgreSQL database | US |
| Google Cloud / BigQuery | Data warehouse for analytics | US |
| Stripe | Billing & payment processing | US |
| Twilio | Call tracking & messaging | US |
| Sentry | Error monitoring | US |
| Calendly | Scheduling | US |