Security & Trust

Here's exactly what we do with your data โ€” and what we never do.

Ledgerline handles bank connections, accounting data, and (optionally) email scanning for fraud detection. Given how sensitive that is, we'd rather over-explain than leave you guessing.

๐Ÿ”’

Read-only bank and accounting access

Ledgerline connects to your bank (via Plaid) and accounting software (QuickBooks, Xero) to read transaction history only. It cannot initiate a transfer, payment, or withdrawal โ€” there is no capability in the product for Ledgerline to move your money.

๐Ÿงพ

Payment holds are advisory, not automatic fund control

When Ledgerline "pauses" a suspicious payment, it means flagging it and prompting you to verify before you release it through your own bank or accounting software โ€” not that Ledgerline itself is holding your funds.

๐Ÿ”‘

No stored bank credentials

We never see or store your online banking username or password. Connections are handled through Plaid's token-based system, the same approach used by major banking and finance apps.

๐Ÿ›ก๏ธ

Encryption at rest and in transit

All financial data is encrypted both while stored and while moving between systems.

About email-layer fraud detection

For businesses that opt in, Ledgerline can scan incoming vendor-related emails (Gmail or Microsoft 365/Outlook) to catch fraud attempts โ€” like a spoofed vendor domain or a suspicious request to change bank details โ€” before a fraudulent invoice is even created. This is optional and requires its own explicit permission, separate from bank/accounting access.

What this feature actually does:

  • Scans for patterns specific to invoice fraud and business email compromise โ€” not general inbox monitoring
  • Requests read-only access (never permission to send, delete, or modify anything in your inbox)
  • Only processes emails for fraud-relevant signals โ€” this is enforced by our own policy and code, since email providers don't offer a way to technically restrict access to just "invoice-looking" emails
  • Stores only the fraud-relevant signal (e.g., sender domain, mentioned bank details) โ€” not a permanent copy of your email content

What Ledgerline never does

  • Move, transfer, or withdraw money on your behalf, under any circumstance
  • Store your bank or email login credentials
  • Send, delete, or modify anything in your email โ€” access (when enabled) is read-only
  • Retain full email content โ€” only fraud-relevant signals are stored, by policy
  • Sell or share your financial or email data with third parties
  • Guarantee against fraud loss โ€” Ledgerline is an advisory tool, not an insurance product (see FAQ below)
Common questions

Is Ledgerline a guarantee against fraud loss?

No. Ledgerline is an advisory and detection tool โ€” it flags and pauses suspicious activity and guides you through verification, but the decision to release a payment is always yours. We do not offer a financial guarantee or insurance against fraud losses.

Can Ledgerline move money without me?

No. All integrations (bank, accounting, email) are read-only. There is no path in the product for Ledgerline to initiate a payment or transfer on its own.

Does email fraud detection technically read my full inbox?

Being direct about this: email providers only let apps request read-only vs. full read/write access โ€” they don't offer a way to technically restrict an app to "just invoice-looking emails." So yes, Ledgerline's software has read access to scan your inbox, but is contractually and technically limited to read-only (it can never send, delete, or modify anything), and by policy only extracts and stores fraud-relevant signals from what it reads โ€” never a retained copy of your full email content.

Do I have to enable email scanning to use Ledgerline?

No โ€” email-layer fraud detection is a separate, optional permission. Cash flow forecasting and bank-side fraud detection work fully without it.

What happens to my data if I cancel?

Disconnecting your accounts revokes Ledgerline's access immediately. Contact us for full data deletion requests.

Is Ledgerline SOC 2 certified?

SOC 2 compliance and audit-log evidence are part of our Enterprise tier roadmap, built specifically for larger businesses with formal security review requirements. Contact us for current status.

Questions we haven't answered here?

We'd rather explain this directly than leave it vague. Reach out any time.

Get early access โ†’