Security
Built around local data and protected accounts.
Ledgora’s most important security decision is simple: your financial working files stay on your computer, not on Ledgora’s servers.
Local-first design
Ledgora Desktop is designed as offline software. Cash-flow forecasts, project files, business records, reports, transactions, receipts, and notes are stored locally on the user’s device. Ledgora does not host those financial files in a cloud database.
Account protection
- Email verification for accounts.
- Optional Google Sign-In and Microsoft Sign-In where configured.
- Optional two-factor authentication with authenticator apps.
- Recovery codes for 2FA account recovery.
- Active session management and sign-out controls.
- Failed-login tracking and rate-limit protections.
- Administrative audit logging for admin actions.
Payments and licenses
Payments are handled through Stripe. Ledgora does not store full card numbers. License activation and update checks use limited license and device activation information; they do not require sending your local financial data.
Downloads and updates
Ledgora’s release system uses controlled download metadata and SHA-256 hashes. Code signing is being added through an organization-validated certificate so Windows can identify Ledgora LLC as the publisher once approved.
No advertising model
Ledgora does not display third-party ads and does not sell user financial data. The business model is software licensing through one-time purchases.
Responsible disclosure
If you believe you found a security issue, contact security@ledgora.app. Please include clear steps to reproduce the issue and avoid accessing or exposing another user’s data.
