Security · technical detail

How Aledgerly protects the books

The plain-language version is on the home page. This page is for accountants, auditors and anyone who wants the specifics.

Sign-in and access

  • Accounts live in Amazon Cognito. Multi-factor authentication is required for every account (TOTP authenticator codes; SMS is not offered). Passwords must be at least 12 characters.
  • Self sign-up is disabled. The owner account and each contractor account are created by invitation only.
  • Step-up re-authentication: high-risk actions — voiding an invoice, inviting a contractor, revealing or changing a tax ID, releasing a closed period, erasing a contact — ask for a fresh code even inside a valid session.
  • Deny by default: every API route must declare exactly one access rule, or the service refuses to start. Contractor identity comes from the signed token, never from what a request claims, and every portal query is scoped to that contractor’s own records.
  • The web app keeps sign-in tokens in memory only — never in localStorage or other browser storage.

Ledger integrity

  • A full double-entry ledger: every transaction’s postings must sum to zero, enforced by the database.
  • Append-only: database triggers reject any update or delete of posted transactions — an application bug cannot rewrite history. Corrections are reversing entries (“Fix this”), and closed periods are locked.
  • Hash-chained audit log: each audit event carries the hash of the one before it, and a uniqueness constraint on that link makes the chain fork-proof. The chain can be verified end to end.

Sensitive data

  • Contractor tax identification numbers are encrypted field by field with AES-256-GCM, using a key stored apart from the database credentials. They display masked (last four digits only), every reveal is written to the audit log, and the key can be rotated.
  • Data is encrypted at rest in AWS (database, file storage and secrets) and travels over HTTPS.
  • Year-end bundles and exports are written to storage with S3 Object Lock: write-once, with a retention period and per-file SHA-256 checksums.
  • Card numbers are never seen or stored — card payments are handled entirely by the payment provider. The app cannot send money: its payment and banking connections read payment records, and the Square connection can also create an invoice for a client to pay.
  • No household Social Security numbers are ever collected.

This website

  • Static pages served from a private bucket through a CDN. No cookies, no analytics, no trackers, no forms, no third-party scripts or fonts.
  • A strict Content-Security-Policy (script-src 'self', nothing inline), HSTS, frame-ancestors 'none' and a locked-down Permissions-Policy.

Honest limits

No system is perfectly secure, and these measures reduce risk rather than remove it. Aledgerly is an in-house tool, not a certified service: it makes no claim of certification or of compliance with any standard. Its tax figures are planning estimates, and it never files or moves money.

Report a security issue

If you believe you’ve found a vulnerability, email texanlinkllc@gmail.com with the details. Please don’t access other people’s data or disrupt the service while testing. See also security.txt.