Skip to content
LedgerDock

Client books, kept the way client books should be kept.

Only what is actually true in the code is claimed on this page. If a control is not built, it is not listed here.

A database schema per company

Every company's ledger, chart of accounts and commits live in their own PostgreSQL schema, created when the company is provisioned. The shared tables that sit above them — users, access, documents, bank connections — are scoped by company and checked on every request.

Every commit hashed and chained

Sealing a commit computes its SHA-256 hash and chains it to the previous one. Every ledger line carries the id of the commit that created it, and a database rule blocks anyone from deleting a line, or changing its amount, date or accounts, once that commit is sealed.

Read-only feeds, encrypted identifiers

Bank and card data arrives two ways: a read-only Plaid feed, or statement files you upload. The Plaid connection reads transactions only — it cannot move money, and LedgerDock never stores your banking login.

Sensitive identifiers — full account numbers, EINs, tax IDs — are encrypted at rest with AES-256-GCM and shown in full only after a separate one-time-code check, which is recorded in the audit log.

Self-hosted models. No third-party AI.

No client data goes to any third-party AI provider. Every model LedgerDock uses — for reading statements and for proposing accounts — is self-hosted and runs on our own hardware.

LedgerDock does use your documents and your corrections to improve those models. They never leave our hardware, and your data is never sold or given to a third party.

A check image is the clearest case. The MICR line along the bottom carries the full account and routing number, so a check image is never sent to any outside service — it is read on our own hardware, and the model is only ever asked for the last four digits.

Logging in

Logging in takes a password plus a one-time code sent by text or email. Passwords are hashed with Argon2id. Once you have passed the code check on a device, LedgerDock remembers it for 30 days; a new device always gets the code. Sessions live server-side and are revalidated on every request, not carried in a cookie.

Hosting, and how to reach us

LedgerDock runs on Railway; documents are stored in AWS S3 with server-side encryption switched on for every upload. The site is served over HTTPS.

Security questions and vulnerability reports: admin@ledgerdock.com. Please write there first and give us a chance to fix an issue before disclosing it.

An accountant's close tool. Month-end, year-end, closed right.