Security
Ledgerline processes confidential loan documents for institutional credit teams. This page describes the controls in place today and the options available on enterprise engagements. We keep this page honest: current capabilities and roadmap items are listed separately.
What is in place today
- Encryption in transit. All traffic to and from Ledgerline is encrypted with TLS.
- Encryption at rest. Stored documents and data are encrypted at rest by our cloud infrastructure providers.
- No model training on customer data. Customer documents and extracted data are never used to train models — ours or any third party's.
- Data retention and deletion. Pilot documents are retained only for the duration of the engagement and deleted on request.
- Access controls. Access to the workspace is authenticated, and each firm's deals and documents are kept separate. Internal access is limited to the team working on your pilot.
- Source-level auditability. Every extracted input links to its original document and page, and every computed metric exposes its formula, assumptions and source inputs — so outputs can be audited line by line.
Available on enterprise engagements
- Private cloud or VPC deployment
- Custom data-retention policies
- Custom integrations with internal systems
Roadmap
We have not yet completed a SOC 2 audit. Formal certifications are on our roadmap as we grow; we are happy to walk your security team through our current architecture and controls in the meantime.
Questions
Security questionnaire or diligence request? Please contact us and we will walk your team through our architecture and controls.