Trust & safety
Security & trust
Your accounting records can include bank statements, invoices, tax information, contact details, and company documents. That kind of data deserves specific controls, not vague assurances.
This page explains the controls currently built into the service and where our assurance boundary stops.
Why it matters
Access should follow responsibility
Business owners need the accounting team to do the work without giving every user the same view or authority. That means access needs to follow the person, business relationship, and task.
PocketLedger separates customer access from accounting-team access, applies role and relationship checks, and records sensitive actions for later review.

What's built in
The controls, in plain language
Grouped by what they protect. No certifications implied — just the controls currently enforced by the service.
Record separation
Business records stay in their accounting workspace
Accounting records are scoped to the workspace providing the service and to the business they belong to. Access checks are applied in the data layer, not left to individual screens.
Business access follows recorded relationships
An authorised customer user can access only the businesses linked to their verified profile. A person linked to one business is not given a view into another.
Access control
Accounting-team access is permission controlled
Day-to-day access is governed by roles and resource-level permissions, separating tasks such as viewing records, approving work, and posting accounting entries.
Protected signed-in sessions
Signed-in sessions use short-lived access with refresh rotation and secure httpOnly cookies. Cookie-authenticated changes require an additional request header for CSRF protection.
One-time-code customer access
Authorised customer users sign in with a one-time code instead of a reusable portal password. Never share that code with anyone, including someone claiming to be PocketLedger.
Data integrity
Audit logging for sensitive actions
Sensitive actions are logged with who did what and when, providing a reviewable history for the actions covered by the log.
Exportable records
Your accounting records remain exportable. Access and export rights follow the agreed service and the permissions applied to the signed-in user.
Retry-safe background processing
Background jobs use retry and idempotency controls so a repeated delivery is not intended to create the same accounting action twice.
Communications
Encrypted in transit
Traffic between supported browsers and PocketLedger services is encrypted with TLS, with HSTS instructing browsers to use secure connections.
Verified inbound webhooks
Inbound WhatsApp webhook requests are signature-verified before processing. Do not use an initial enquiry to send passwords, one-time codes, or unnecessary identity documents.
Where we're headed
Honest about today, working on tomorrow
We don't yet hold formal certifications such as SOC 2 or ISO 27001 — they are on our roadmap as the service and the team grow. We would rather say that plainly than decorate this page with badges.
What we can do today is walk you through our current posture in detail — how record separation, access control, and auditing work. Contact us; it's a conversation we welcome having.
Common questions
What business owners ask about security
Customer access is restricted to businesses linked to the signed-in person's verified profile. Accounting records are also scoped to the accounting workspace and business they belong to, with access checks applied in the data layer.

Ask us the hard questions
Bring your security checklist to a conversation — we'll walk through each control with you.