FinLedgic
FeaturesPricingLog inStart free trial
← Back to home

Security

Last updated July 22, 2026

Protecting your financial data is foundational to FinLedgic. Here's how we keep it safe.

Bank credentials are never ours to lose

Bank connections are handled through Plaid. You enter your online-banking credentials directly with your bank via Plaid’s secure flow. FinLedgic never sees, receives, or stores them. We only hold a scoped access token, and we hold it encrypted with AES-256-GCM.

Encryption

  • In transit: all traffic is served over HTTPS/TLS.
  • At rest: access tokens are encrypted with authenticated AES-256-GCM; passwords are stored only as bcrypt hashes, never in plain text.

Access & authentication

Sessions use signed, http-only cookies. Every application route is guarded server-side, and financial totals are always recomputed on the server. The browser is never trusted for money math.

Infrastructure

FinLedgic runs on reputable, SOC-2-aligned infrastructure providers for hosting, database, payments (Stripe), and bank connectivity (Plaid). Secrets are stored as environment configuration, never in source code.

Read-only banking

Our bank connection is used only to read transactions and balances. FinLedgic cannot move money or initiate transfers from your connected accounts.

Governance

Information security is owned and overseen by FinLedgic’s leadership. We maintain documented security and privacy practices (this page and our Privacy Policy), and we review them at least annually and when we make material changes to how we handle data.

Access control

  • Least privilege: access to systems that store or process customer financial data is limited to the individuals who need it to operate the service.
  • Unique accounts: each operator uses their own named account on our hosting, database, and code platforms; we do not share credentials.
  • Multi-factor authentication is required for administrative access to the production systems that store customer data (hosting, database, and source control).
  • Secrets (API keys, encryption keys, database credentials) are stored as protected environment configuration, never committed to source code.
  • Periodic access reviews: access to production systems is reviewed at least annually and adjusted or revoked when it is no longer required.

Vulnerability & patch management

Application dependencies are automatically monitored for known vulnerabilities and updated promptly when issues are identified. We prioritize remediation by severity, addressing critical vulnerabilities on an expedited basis, and we monitor for and retire end-of-life software and dependencies. Our production hosting and database run on managed, SOC-2-aligned platforms that patch the underlying operating systems and infrastructure. We apply a strict Content-Security-Policy and standard security headers (HSTS, X-Frame-Options, X-Content-Type-Options) across the application.

Incident response

We maintain a process to detect, investigate, and contain security incidents. If an incident affects your data, we will notify affected users and any required authorities without undue delay, consistent with applicable law.

Data retention & deletion

We retain data only as long as needed to provide the service or meet legal obligations, and we honor deletion requests. The full schedule, including timelines, is in our Privacy Policy, which is reviewed at least annually.

Service providers (sub-processors)

We rely on a small set of reputable providers, each bound by contractual security and confidentiality obligations: Plaid (bank connectivity), Stripe (payments), and our hosting, database, and email providers. We share the minimum data necessary for each to perform its function, and we never sell customer data.

Reporting a vulnerability

If you believe you’ve found a security issue, please email security@finledgic.com. We appreciate responsible disclosure and will respond promptly.

FinLedgic

Bank-connected bookkeeping and invoicing for small businesses.

Product

FeaturesInvoicingPricingLog in

Support

Help CenterSecurityAccessibility

Legal

Privacy PolicyTerms of ServiceLegal DisclosuresLicensing
© 2026 FinLedgic. All rights reserved.PrivacyTermsAccessibility