Security at LedgerChase
Translations are provided for convenience. If a translation differs from the English version, the English version controls unless applicable law requires otherwise.
Security contact: [email protected].
Controls
- TLS in transit, strict transport and browser security headers in production.
- Production readiness requires strong password hashing, session revocation, MFA for privileged accounts, and a verified Redis-backed rate-limit service.
- Tenant and team authorization checks, least-privilege roles and audit events for sensitive actions.
- Private randomized upload paths, size/type/header checks, archive-bomb defenses, hashes and fail-closed malware scanning in production.
- Production readiness requires PostgreSQL with restricted access, encryption at rest and encrypted backups, plus a successful recovery test. Active providers are disclosed only after verification.
- Secrets remain in production environment configuration and are excluded from release bundles.
Limits and incident response
No security program eliminates all risk. We monitor, contain, preserve evidence, remedy and assess notification duties when a suspected incident occurs. We notify affected customers and authorities where legally required. Customers remain responsible for endpoint security, lawful access and reviewing team permissions.
Report concerns
Do not include real customer data in an initial report. Read and follow our Vulnerability Disclosure Policy and reporting instructions before testing or sending a report.