How LedgR protects client data.
For advisors, and for the compliance consultants who check their vendors. Each point on this page describes what LedgR’s own code enforces, not what a policy hopes for.
Open to founding firms. LedgR is live, by invitation, for a few founding firms first. What follows is how it is built. Anything still to come is marked as coming. Updated .
At a glance
Each one takes you to its section.- Sign-inInvite-only, with Google sign-in and a verified emailDetails ↓
- SeparationEach firm walled off from every other by the database’s own rulesDetails ↓
- RolesThe owner decides what each assistant can doDetails ↓
- RecordsNotes are corrected as new versions, never rewrittenDetails ↓
- Activity logEvery change is logged by the server, and nobody can edit the logDetails ↓
- ExportAll of your firm’s records in one download, whenever you askDetails ↓
- Where it livesGoogle Cloud in the United States, and not on your devicesDetails ↓
- IncidentsNotice within 72 hours of us becoming aware of an incident affecting your firm’s client informationDetails ↓
Only the people you invite get in.
Invite-only
A firm’s owner invites each person by email address. LedgR lets someone into a firm only if there is a pending invitation for that exact address. There is no public sign-up: firms are set up by LedgR directly.
Google sign-in, with a verified email
People sign in with their Google account, and the email on it must be verified by Google. Anyone else who signs in sees “You haven’t been invited” and no data.
Firm and role are set by the server
Which firm a person belongs to, and whether they are an owner or an assistant, is set by LedgR’s server when they accept their invitation. Nothing the browser sends can change it.
Removing someone works at once
When an owner removes a team member, their very next request is refused, even before their current sign-in would have expired, and their sessions can no longer be renewed.
Each firm’s data is walled off from every other.
Every record belongs to one firm
Clients, notes, follow-ups, tasks, pipeline cards and the activity log all live under their firm. The database’s security rules let a person read or write them only as an active member of that firm.
Anything not allowed is refused
The rules allow specific things and deny everything else, including any attempt to read across firms or to list firms.
Every write is checked, field by field
Only known fields are accepted, each with the right type and size. The author and time stamped on a record must be the person actually signed in and the server’s own clock.
Tested from the attacker’s side
Automated tests run the rules as an outsider, a signed-in stranger, an owner from another firm trying to reach in, a removed team member and an assistant, and check that each is refused what it should be.
Owners and assistants share the clients, not the controls.
Assistants do the daily work. The owner decides, step by step, whether an assistant may also manage the team, import, export, delete clients, retract notes or rename the firm.
| In LedgR | Owner | Assistant |
|---|---|---|
| Work with clients, notes, follow-ups, tasks and the pipeline | Yes | Yes |
| Invite or remove team members | Yes | If the owner allows it |
| See pending invitations | Yes | If the owner allows it |
| Import a spreadsheet of leads | Yes | If the owner allows it |
| Export all of the firm’s records | Yes | If the owner allows it |
| Delete a client | Yes | If the owner allows it |
| Retract a note | Yes | If the owner allows it |
| Rename the firm | Yes | If the owner allows it |
Each of these steps is checked twice: against the role LedgR’s server gave the person, and against their live membership record, where the owner’s choices are kept. A change takes effect on the assistant’s very next request, and only the owner can make it.
Fix a note without rewriting the record.
A correction is a new version
Fix a typo or a wrong detail and LedgR saves the fix as a new version. The note shows the latest wording, marked Corrected, and every earlier version stays one tap away with who wrote it and when.
Retract with a reason
A note on the wrong client can be retracted. It folds to one line saying who retracted it and why, and the original can still be opened. Owners can retract; an assistant can if the owner allows it.
Deleting a client archives their records
Deleting a client goes through LedgR’s server. Their notes, follow-ups, tasks and pipeline cards are archived, not erased, and kept for five years, in line with the SEC’s books-and-records rule for advisers. The owner can see every deleted client, and the deletion is logged.
Archived messages will be read-only Coming
Email and text archiving comes in a later phase. The rules are already in place: only LedgR’s server can write those records, and nobody in the firm can change them.
Every change, logged by the server.
Who, what and when
Adding or changing a client, follow-up, task or pipeline card, and adding a note, is recorded by LedgR’s server: who did it, what it was, and when. For an edit, the log keeps which fields changed, from what to what. A spreadsheet import is logged as one entry per imported client.
Nobody can edit the log
Entries can’t be changed or deleted from the app by anyone in the firm. Change entries are written by the server, never by a browser.
Access and exports are logged too
Invitations, people joining, removals, exports and client deletions each leave an entry naming who did it.
The log doesn’t copy your notes
It records that a note was added to a client, not what the note says.
Views are logged, and labelled honestly
Opening a client’s record is logged by the app as well. Because a tampered browser could skip that step, those entries are marked best-effort. Changes can’t be skipped.
Your firm’s records, whenever you ask.
One download, everything in it
The owner can export all of the firm’s records in one zip: clients, notes and their corrections, retractions, follow-ups, tasks, pipeline cards, the activity log and the team list, as a JSON file plus a spreadsheet file for each.
Allowed, and logged
An assistant can export only if the owner allows it. Each export is recorded in the activity log with who ran it.
Safe to open in a spreadsheet
Any cell a spreadsheet could run as a formula is neutralized before it is written.
In the United States, and not on your devices.
Google Cloud, in the United States
LedgR’s database is Google Cloud Firestore in the nam5 location, a multi-region within the United States. LedgR’s server code runs in Google Cloud’s us-central1 region.
No client data saved to the device
LedgR’s web app keeps client records in memory while it is open and does not save a copy to the computer’s or phone’s storage. Only your sign-in and display preference are remembered, so a refresh doesn’t sign you out.
If something goes wrong, you hear from us.
72 hours
We will notify your firm within 72 hours of becoming aware of a security incident that affects your firm’s client information.