Last updated: July 29, 2026
LedgerHelm handles bookkeeping records, financial statements, and tax data on behalf of small businesses and the accounting firms that serve them. Protecting that data is foundational to the product. This page summarizes our security practices; customers evaluating us for vendor review can request our detailed security documentation through the contact options below.
Data is encrypted in transit using TLS. Data at rest — including the primary database and uploaded documents — is encrypted using industry-standard encryption provided by our infrastructure and storage providers. Sensitive identifiers collected for tax filing (such as taxpayer identification numbers) are additionally encrypted at the application layer.
LedgerHelm is a multi-tenant application. Each customer’s data is segregated and access is enforced at the database layer using row-level security, so a request executing for one tenant cannot read or write another tenant’s records. This isolation is applied to the money engine, documents, and reporting alike.
Access to the application is governed by role-based access control: business owners, bookkeepers, accounting-firm staff, and platform administrators each receive only the permissions their role requires. Actions that affect the books or sensitive settings are restricted to authorized roles, and administrative access to production systems is limited to personnel who need it.
Security-relevant and financially-relevant actions are recorded in an audit log. We monitor application health and errors and investigate anomalies. Our double-entry ledger is designed so that the books remain internally consistent (debits equal credits, subledgers tie to the general ledger), which also surfaces unexpected data changes.
LedgerHelm does not store raw payment-card numbers and does not take custody of customer funds. Card payments are processed by Stripe, a PCI-DSS Level 1 provider. Tax and information-return e-filing is performed by licensed partners (for example, an IRS-authorized e-file provider for 1099/W-2 and payroll returns, and licensed preparers for income-tax returns). See our Subprocessors page for the current list of providers.
As a company that handles consumers’ financial and tax information, we maintain an information-security program consistent with applicable data-protection obligations. Our collection, use, and sharing of personal information is described in our Privacy Policy. You control your data and can export or request deletion of it, subject to records we must retain by law.
Arkenly LLC is building toward a SOC 2 examination of the LedgerHelm platform covering the Security (and, as the program matures, Availability and Confidentiality) Trust Services Criteria. Prospective customers can request the current status of our SOC 2 program and, once available, our report under NDA.
If you believe you have found a security vulnerability, please report it to us promptly through our contact page rather than disclosing it publicly. We appreciate responsible disclosure and will work with you to validate and remediate confirmed issues.