Financial systems hold exactly what attackers want: bank details, customer and supplier data, and the numbers that move money. Security in Ledgestra starts from one principle: protect the data itself, not just the screen in front of it.
Your data never crosses company lines
Many applications only check whether a user can open a page. That protects the menu, not the data behind it. In Ledgestra, company separation is enforced on the data itself, on every request. Records belonging to one company can't be read from another company's account, whether through the app or by trying to work around it.
Access that matches responsibility
- Roles and permissions: each user reaches only the modules and pages their role allows, within their own company.
- Module-level control: an administrator switches entire modules or sub-modules on or off for each company.
- Nothing visible-but-blocked: pages a user can't access don't appear in their navigation.
Verified sign-in
Accounts use real, server-verified logins, and users can turn on multi-factor authentication for a second check at sign-in. Invitations and password resets go through dedicated, admin-controlled flows rather than shortcuts.
A complete record of who did what
The audit log captures changes to records across the application: who changed what, when, and what the values were before and after. Imports and exports are logged too, so you always know what data left the system and who took it.
Sensitive data stays protected
Bank account details and other sensitive credentials are kept encrypted and handled on the server, never exposed to the browser. Administrative operations run through a separate, tightly controlled path, kept apart from everyday use.
Controls built into the accounting
Security also means integrity. Posted journal entries and stock movements are corrected by reversing, not by editing. Deleted documents stay visible in their own report, and reports flag unposted and unbalanced entries. The books themselves resist silent changes.
For a deeper look, see our Security page, or talk to us about your own requirements.