Ledgerline handles bank connections, accounting data, and (optionally) email scanning for fraud detection. Given how sensitive that is, we'd rather over-explain than leave you guessing.
Ledgerline connects to your bank (via Plaid) and accounting software (QuickBooks, Xero) to read transaction history only. It cannot initiate a transfer, payment, or withdrawal โ there is no capability in the product for Ledgerline to move your money.
When Ledgerline "pauses" a suspicious payment, it means flagging it and prompting you to verify before you release it through your own bank or accounting software โ not that Ledgerline itself is holding your funds.
We never see or store your online banking username or password. Connections are handled through Plaid's token-based system, the same approach used by major banking and finance apps.
All financial data is encrypted both while stored and while moving between systems.
For businesses that opt in, Ledgerline can scan incoming vendor-related emails (Gmail or Microsoft 365/Outlook) to catch fraud attempts โ like a spoofed vendor domain or a suspicious request to change bank details โ before a fraudulent invoice is even created. This is optional and requires its own explicit permission, separate from bank/accounting access.
What this feature actually does:
No. Ledgerline is an advisory and detection tool โ it flags and pauses suspicious activity and guides you through verification, but the decision to release a payment is always yours. We do not offer a financial guarantee or insurance against fraud losses.
No. All integrations (bank, accounting, email) are read-only. There is no path in the product for Ledgerline to initiate a payment or transfer on its own.
Being direct about this: email providers only let apps request read-only vs. full read/write access โ they don't offer a way to technically restrict an app to "just invoice-looking emails." So yes, Ledgerline's software has read access to scan your inbox, but is contractually and technically limited to read-only (it can never send, delete, or modify anything), and by policy only extracts and stores fraud-relevant signals from what it reads โ never a retained copy of your full email content.
No โ email-layer fraud detection is a separate, optional permission. Cash flow forecasting and bank-side fraud detection work fully without it.
Disconnecting your accounts revokes Ledgerline's access immediately. Contact us for full data deletion requests.
SOC 2 compliance and audit-log evidence are part of our Enterprise tier roadmap, built specifically for larger businesses with formal security review requirements. Contact us for current status.
We'd rather explain this directly than leave it vague. Reach out any time.
Get early access โ