Ledge has been included on the 2024 Fintech Innovation 50 list!
Learn more

Security & compliance

Enterprise security, built into every workflow

Ledge is built for finance teams handling sensitive accounting data. Security is not an add-on. It is foundational to how the platform operates.

πŸ›‘ SOC 1 Β· πŸ›‘ SOC 2 Β· βœ“ ISO 42001 Β· πŸ”’ GDPR

β›”

Your data is never used to train AI models

Ledge processes customer data exclusively to execute accounting workflows within your environment. No customer data is used for model training, shared across customers, or accessed by other tenants.

Data handling

How Ledge processes your data

Your data stays in your environment, protected by layered security controls.

πŸ–₯️ AI that writes code, not guesses

Ledge AI writes bespoke code for each workflow. Once written, that code runs the same way every period. Auditable, repeatable, and explainable. βœ“ Same code, same results every close βœ“ No variable outputs or hallucinations βœ“ Glass-box logic visible at every step

πŸ›‘οΈ Enterprise security practices

Ledge protects your financial data with layered security controls across infrastructure, access, and operations. βœ“ Encryption in transit and at rest βœ“ Periodic third-party penetration testing βœ“ Data isolation between customers

Access controls

Enterprise-grade identity and permissions

Integrates with your existing identity infrastructure and enforces granular, role-based permissions across your entire finance team.

πŸ”’ Single sign-on

Integrates with your existing identity provider

πŸ‘₯ Role-based access

Granular permissions for who can view, edit, approve, and post

βœ… Flexible approvals

Use your existing NetSuite routing, approve in Ledge and auto-post, or require dual approval in both

πŸ‘€ Unlimited users

Your full team accesses the platform without security gated by licensing

βœ“ Certified NetSuite SuiteApp

Ledge ↔ NetSuite Bi-directional sync Read: GL, segments, transactions Write: JE posting only (human-approved)

NetSuite integration

Certified SuiteApp, not custom API connections

Ledge is a Certified NetSuite SuiteApp (Built for NetSuite). The integration uses continuous bi-directional sync through NetSuite’s official SuiteApp framework, not custom API connections or third-party middleware. βœ“ Read access to GL accounts, segments, subsidiaries, and transactions βœ“ Write access for JE posting, only after human approval βœ“ Auto-detection without modifying NetSuite configuration βœ“ Full traceability: every action, comment, and approval logged

Audit trail

Glass-box audit trail, built as you close

Ledge produces a complete, traceable record for every workflow. No separate audit prep project required. βœ“ Full traceability: every agent action is logged with data, logic, and output βœ“ Working paper lineage: source data tabs, live formulas, and rollforwards βœ“ Human-in-the-loop: nothing posts without explicit human approval βœ“ Flexible authorization: use your existing NetSuite routing, approve in Ledge with auto-post, or dual approval

Audit log: Prepaid insurance rec

09:01 Agent pulled GL balance from NetSuite 09:01 Agent built workpaper with rollforward 09:02 $2,450 variance flagged for review 09:14 Sarah Chen approved in Ledge 09:15 Re-approved and posted in NetSuite

Vendor review

We make security review easy

Your IT and legal teams can evaluate Ledge quickly with everything they need in one place.

πŸ”— Trust center

Self-serve access to SOC reports, compliance certifications, and security policies

πŸ” Penetration testing

Annual third-party penetration test reports available under NDA

πŸ“„ Data processing agreement

Standard DPA available for review and execution

FAQ

Questions your security team will ask

Where does our data live?

Ledge operates on cloud infrastructure with encryption at rest and in transit. Detailed infrastructure documentation is available at trust.ledge.co.

Does Ledge have write access to our NetSuite instance?

Yes, but only for journal entry posting, and only after explicit human approval. You choose the approval model: use your existing NetSuite approval routing, approve in Ledge and auto-post, or require dual approval in both systems. All other interactions are read-only.

Is customer data used to train your AI models?

No. Customer data is never used for model training. It is processed exclusively within your environment to execute your accounting workflows.

Can we review your SOC 2 report?

Yes. SOC 1 and SOC 2 reports are available through trust.ledge.co or upon request from your account team.

Does Ledge support our identity provider?

Yes. Ledge supports SSO and integrates with your existing identity provider. Contact your account team to confirm compatibility.

Ready to see Ledge in your environment?

Talk to our team about your security requirements. We will get your IT and legal teams everything they need.

Ledge

We're on a mission to automate and simplify finance operations for teams working at scale.

New York

325 Hudson St, New York, United States 10013

Tel Aviv

Leonardo da Vinci St 14
Tel Aviv, Israel
6473118