LedgR
Coming soonEarly access
Security

How LedgR protects client data.

For advisors, and for the compliance consultants who check their vendors. Each point on this page describes what LedgR’s own code enforces, not what a policy hopes for.

Open to founding firms. LedgR is live, by invitation, for a few founding firms first. What follows is how it is built. Anything still to come is marked as coming. Updated .

At a glance

Each one takes you to its section.
Sign-in

Only the people you invite get in.

  • Invite-only

    A firm’s owner invites each person by email address. LedgR lets someone into a firm only if there is a pending invitation for that exact address. There is no public sign-up: firms are set up by LedgR directly.

  • Google sign-in, with a verified email

    People sign in with their Google account, and the email on it must be verified by Google. Anyone else who signs in sees “You haven’t been invited” and no data.

  • Firm and role are set by the server

    Which firm a person belongs to, and whether they are an owner or an assistant, is set by LedgR’s server when they accept their invitation. Nothing the browser sends can change it.

  • Removing someone works at once

    When an owner removes a team member, their very next request is refused, even before their current sign-in would have expired, and their sessions can no longer be renewed.

Separation

Each firm’s data is walled off from every other.

  • Every record belongs to one firm

    Clients, notes, follow-ups, tasks, pipeline cards and the activity log all live under their firm. The database’s security rules let a person read or write them only as an active member of that firm.

  • Anything not allowed is refused

    The rules allow specific things and deny everything else, including any attempt to read across firms or to list firms.

  • Every write is checked, field by field

    Only known fields are accepted, each with the right type and size. The author and time stamped on a record must be the person actually signed in and the server’s own clock.

  • Tested from the attacker’s side

    Automated tests run the rules as an outsider, a signed-in stranger, an owner from another firm trying to reach in, a removed team member and an assistant, and check that each is refused what it should be.

Roles

Owners and assistants share the clients, not the controls.

Assistants do the daily work. The owner decides, step by step, whether an assistant may also manage the team, import, export, delete clients, retract notes or rename the firm.

What owners and assistants can do in LedgR
In LedgROwnerAssistant
Work with clients, notes, follow-ups, tasks and the pipelineYesYes
Invite or remove team membersYesIf the owner allows it
See pending invitationsYesIf the owner allows it
Import a spreadsheet of leadsYesIf the owner allows it
Export all of the firm’s recordsYesIf the owner allows it
Delete a clientYesIf the owner allows it
Retract a noteYesIf the owner allows it
Rename the firmYesIf the owner allows it

Each of these steps is checked twice: against the role LedgR’s server gave the person, and against their live membership record, where the owner’s choices are kept. A change takes effect on the assistant’s very next request, and only the owner can make it.

Records

Fix a note without rewriting the record.

  • A correction is a new version

    Fix a typo or a wrong detail and LedgR saves the fix as a new version. The note shows the latest wording, marked Corrected, and every earlier version stays one tap away with who wrote it and when.

  • Retract with a reason

    A note on the wrong client can be retracted. It folds to one line saying who retracted it and why, and the original can still be opened. Owners can retract; an assistant can if the owner allows it.

  • Deleting a client archives their records

    Deleting a client goes through LedgR’s server. Their notes, follow-ups, tasks and pipeline cards are archived, not erased, and kept for five years, in line with the SEC’s books-and-records rule for advisers. The owner can see every deleted client, and the deletion is logged.

  • Archived messages will be read-only Coming

    Email and text archiving comes in a later phase. The rules are already in place: only LedgR’s server can write those records, and nobody in the firm can change them.

Activity log

Every change, logged by the server.

  • Who, what and when

    Adding or changing a client, follow-up, task or pipeline card, and adding a note, is recorded by LedgR’s server: who did it, what it was, and when. For an edit, the log keeps which fields changed, from what to what. A spreadsheet import is logged as one entry per imported client.

  • Nobody can edit the log

    Entries can’t be changed or deleted from the app by anyone in the firm. Change entries are written by the server, never by a browser.

  • Access and exports are logged too

    Invitations, people joining, removals, exports and client deletions each leave an entry naming who did it.

  • The log doesn’t copy your notes

    It records that a note was added to a client, not what the note says.

  • Views are logged, and labelled honestly

    Opening a client’s record is logged by the app as well. Because a tampered browser could skip that step, those entries are marked best-effort. Changes can’t be skipped.

Export

Your firm’s records, whenever you ask.

  • One download, everything in it

    The owner can export all of the firm’s records in one zip: clients, notes and their corrections, retractions, follow-ups, tasks, pipeline cards, the activity log and the team list, as a JSON file plus a spreadsheet file for each.

  • Allowed, and logged

    An assistant can export only if the owner allows it. Each export is recorded in the activity log with who ran it.

  • Safe to open in a spreadsheet

    Any cell a spreadsheet could run as a formula is neutralized before it is written.

Where it lives

In the United States, and not on your devices.

  • Google Cloud, in the United States

    LedgR’s database is Google Cloud Firestore in the nam5 location, a multi-region within the United States. LedgR’s server code runs in Google Cloud’s us-central1 region.

  • No client data saved to the device

    LedgR’s web app keeps client records in memory while it is open and does not save a copy to the computer’s or phone’s storage. Only your sign-in and display preference are remembered, so a refresh doesn’t sign you out.

Incidents

If something goes wrong, you hear from us.

  • 72 hours

    We will notify your firm within 72 hours of becoming aware of a security incident that affects your firm’s client information.

Live

Switched on with the app.

These went live with the app on 6 October 2026.

  • App Check Live

    Firebase App Check with reCAPTCHA Enterprise, so LedgR’s backend answers only its own app. LedgR’s server functions refuse requests without it from the first day; the database and sign-in follow once the app has been checked in daily use.

  • Backups and point-in-time recovery Live

    Point-in-time recovery for the last seven days, a daily backup kept for fourteen weeks, and protection against the database itself being deleted.

  • A strict content security policy Live

    The app’s pages may load scripts and connect only to the addresses LedgR needs, which limits what injected code could do.

  • A long-term records archive Live

    A copy of the whole database kept for six years in a separate archive, for books-and-records retention. The first copy was taken at launch.

Questions from your compliance consultant?

Ask about early access and Caleb will answer them personally.

Ask about early access

LedgR is opening to a few founding firms first. Tell us a little about yours and Caleb will reach out personally.

We’ll only use this to get in touch about LedgR.

Thanks.

Your note is on its way to Caleb. He’ll be in touch soon.