
Overview
At LedgerSync, we prioritize security with robust measures to protect our clients’ data. Here is an overview of our security protocols.
1. User/Password Security
LedgerSync does not store user/password information when using the Mastercard API. Bank credentials are entered directly with the bank or aggregator — they never pass through or rest on LedgerSync’s servers. Access is granted via secure tokens that the client authorizes and the bank controls.
2. Two-Factor Authentication (2FA)
LedgerSync supports authenticator-app based 2FA (e.g., Google Authenticator) on the main product login. With 2FA enabled, a password alone is not enough to access an account. See:
Two-Factor Authentication (2FA) Setup
3. Automatic Session Timeout
Inactive sessions are automatically logged out: after 10 minutes without interaction a warning appears with a 5-minute countdown, and the session ends if there is no response. This protects data on shared or unattended computers. See:
Automatic Session Timeout
4. Role-Based Access Controls
- Employees see only the clients assigned to them; administrators control assignments
- Firms using the Accounting Firm layer can restrict employee visibility per firm
- Powerful bulk actions are restricted by role — for example, the AI Bulk Rules Engine update is limited to admin and super-admin users only
- An audit log records who made changes in the Rules Engine and when
5. Sensitive Data Masking
Routing and account numbers are blocked out on check images displayed in LedgerSync, so full banking details are not exposed to everyone who can view a check.
6. Data Encryption
All data is encrypted in transit (TLS) and at rest. Bank data is retrieved through regulated aggregators (Mastercard Open Finance and MX) that maintain their own bank-grade security and compliance programs.
7. Read-Only Bank Access
LedgerSync connections are read-only. No one — not your staff, not LedgerSync — can move money, pay bills, or change anything at the bank through a LedgerSync connection. The connection can only view statements, transactions, and balances the client authorized.
8. Compliance Documentation
Need Help?