
Overview
At LedgerSync, we prioritize security with robust measures to protect our clients’ data. Here is an overview of our security protocols.
1. User/Password Security
LedgerSync does not store user/password information when using the Mastercard API. Bank credentials are entered directly with the bank or aggregator — they never pass through or rest on LedgerSync’s servers. Access is granted via secure tokens that the client authorizes and the bank controls.
2. Two-Factor Authentication (2FA)
LedgerSync supports authenticator-app based 2FA (e.g., Google Authenticator) on the main product login. With 2FA enabled, a password alone is not enough to access an account. See:
Two-Factor Authentication (2FA) Setup
3. Automatic Session Timeout
Inactive sessions are automatically logged out: after 10 minutes without interaction a warning appears with a 5-minute countdown, and the session ends if there is no response. This protects data on shared or unattended computers. See:
Automatic Session Timeout
4. Role-Based Access Controls
- Employees see only the clients assigned to them; administrators control assignments
- Firms using the Accounting Firm layer can restrict employee visibility per firm
- Powerful bulk actions are restricted by role — for example, the AI Bulk Rules Engine update is limited to admin and super-admin users only
- An audit log records who made changes in the Rules Engine and when
5. Sensitive Data Masking
Routing and account numbers are blocked out on check images displayed in LedgerSync, so full banking details are not exposed to everyone who can view a check.
6. Data Encryption
All data is encrypted in transit (TLS) and at rest. Bank data is retrieved through regulated aggregators (Mastercard Open Finance and MX) that maintain their own bank-grade security and compliance programs.
7. Read-Only Bank Access
LedgerSync connections are read-only. No one — not your staff, not LedgerSync — can move money, pay bills, or change anything at the bank through a LedgerSync connection. The connection can only view statements, transactions, and balances the client authorized.
8. Compliance Documentation
Need Help?
Related Articles
LedgerSync Close — Overview and How It Works
Overview LedgerSync Close is a month-end reconciliation tool that compares your bank statements directly against the transactions recorded in QuickBooks Online (QBO). It automatically identifies missing transactions, duplicate entries, and category ...
MX Bank Connection — Overview, Setup, and FAQ
Overview MX is LedgerSync's second full bank data aggregator, available alongside the Mastercard API. MX is fully deployed and actively used across the platform — it is not a beta feature. If your bank is not supported by the Mastercard API, or if ...
How to Report a Bank Connection Bug in LedgerSync
Purpose: This guide walks you through reporting a problem with a bank connection in LedgerSync. Submitting a bug report creates a support ticket for the LedgerSync Customer Service team and sends you a confirmation email so we can investigate and get ...
Bank Connection Notes — How to Add Shared Notes to a Bank Connection
Overview The Notes feature lets you attach persistent, shared notes to any bank connection in LedgerSync — whether it is connected via Mastercard, MX, or FDE (document-based extraction). Notes are visible to all users in your firm and are a great way ...
If a bank has already been connected, will all new accounts be auto added to Ledgersync?
If a client already connected a bank to Ledgersync and the client adds new accounts under the same login details, will the new accounts be added automatically in Ledgersync? It’s a very good question and the answer depends on the type of connection ...