Abstract financial data visualization with glowing blue grid lines on dark background
PRIVACY_POLICY · EFFECTIVE_FEB_2026

Your financial data.
Every decimal accounted for.

This is Ledger's complete privacy policy — written for the small business owner who just handed over their QuickBooks credentials, not for a compliance team. Explore it by topic, not by page.

0
Data brokers we use
AES-256
Encryption standard
72hr
Breach notification
7yr
Max retention
EXPLORE_BELOW
TRANSPARENCY_REPORT

We know what we hold.
So should you.

Every data point we hold on your business is documented here — in plain English, not legalese. Click any card to expand the full policy.

SOC_2_TYPE_2
AES_256
GLBA_COMPLIANT
1099-NECQuickBooksAES-256
DATA_FLOW_MAP · LIVE
ALL_PATHS_ENCRYPTED

Your data map, documented.

Every pathway your financial data travels through Ledger's systems — from your upload to authorized filing. No undocumented routes.

You
Client upload
Ledger Portal
Encrypted ingestion
AWS GovCloud
AES-256 at rest
Your CPA
MFA-gated access
IRS / State
Authorized filing only
0
Third-party ad networks
7yr
Max retention period
72hr
Breach notification SLA
100%
US-only data residency
COMPLIANCE_REGISTRY

Audited, certified, and
documented in full.

These aren't aspirational badges. Each represents a completed audit, an active certification, or an ongoing technical control.

CERTIFIED

SOC 2 Type 2

Annual audit by independent PCAOB-registered firm. Report available to clients on request.

LAST_VERIFIED2025
COMPLIANT

GLBA Safeguards

Full compliance with Gramm-Leach-Bliley Act including 2023 amended safeguards rule.

LAST_VERIFIED2026
VERIFIED

IRS Pub. 4557

All 12 required data security safeguards implemented and documented for tax preparers.

LAST_VERIFIED2026
ACTIVE

AES-256 Encryption

NIST-recommended encryption standard applied to all data at rest and in transit.

LAST_VERIFIEDONGOING
AUTHORIZED

FedRAMP Moderate

AWS GovCloud infrastructure meets FedRAMP Moderate authorization requirements.

LAST_VERIFIED2025
PASSED

Annual Pen Test

Independent third-party penetration testing conducted annually. No critical findings in 4 years.

LAST_VERIFIED2025

Compliance reports are available to clients on request. Email compliance@ledger.cpa with your engagement ID. SOC 2 report, pen test executive summary, and GLBA safeguards documentation will be delivered within 2 business days.