Skip to content

Trust & safety

Security & trust

Your accounting records can include bank statements, invoices, tax information, contact details, and company documents. That kind of data deserves specific controls, not vague assurances.

This page explains the controls currently built into the service and where our assurance boundary stops.

Why it matters

Access should follow responsibility

Business owners need the accounting team to do the work without giving every user the same view or authority. That means access needs to follow the person, business relationship, and task.

PocketLedger separates customer access from accounting-team access, applies role and relationship checks, and records sensitive actions for later review.

Two people signing a contract at a desk

What's built in

The controls, in plain language

Grouped by what they protect. No certifications implied — just the controls currently enforced by the service.

Record separation

Business records stay in their accounting workspace

Accounting records are scoped to the workspace providing the service and to the business they belong to. Access checks are applied in the data layer, not left to individual screens.

Business access follows recorded relationships

An authorised customer user can access only the businesses linked to their verified profile. A person linked to one business is not given a view into another.

Access control

Accounting-team access is permission controlled

Day-to-day access is governed by roles and resource-level permissions, separating tasks such as viewing records, approving work, and posting accounting entries.

Protected signed-in sessions

Signed-in sessions use short-lived access with refresh rotation and secure httpOnly cookies. Cookie-authenticated changes require an additional request header for CSRF protection.

One-time-code customer access

Authorised customer users sign in with a one-time code instead of a reusable portal password. Never share that code with anyone, including someone claiming to be PocketLedger.

Data integrity

Audit logging for sensitive actions

Sensitive actions are logged with who did what and when, providing a reviewable history for the actions covered by the log.

Exportable records

Your accounting records remain exportable. Access and export rights follow the agreed service and the permissions applied to the signed-in user.

Retry-safe background processing

Background jobs use retry and idempotency controls so a repeated delivery is not intended to create the same accounting action twice.

Communications

Encrypted in transit

Traffic between supported browsers and PocketLedger services is encrypted with TLS, with HSTS instructing browsers to use secure connections.

Verified inbound webhooks

Inbound WhatsApp webhook requests are signature-verified before processing. Do not use an initial enquiry to send passwords, one-time codes, or unnecessary identity documents.

Where we're headed

Honest about today, working on tomorrow

We don't yet hold formal certifications such as SOC 2 or ISO 27001 — they are on our roadmap as the service and the team grow. We would rather say that plainly than decorate this page with badges.

What we can do today is walk you through our current posture in detail — how record separation, access control, and auditing work. Contact us; it's a conversation we welcome having.

Common questions

What business owners ask about security

Customer access is restricted to businesses linked to the signed-in person's verified profile. Accounting records are also scoped to the accounting workspace and business they belong to, with access checks applied in the data layer.

Ask us the hard questions

Bring your security checklist to a conversation — we'll walk through each control with you.