Save 50% on your first bill

Security & trust

Security and Compliance Controls

A scoped view of current controls and deployment options, plus certifications that remain on the roadmap. Capabilities vary by plan, feature, and deployment; request trust materials for your specific requirements.
Current controls · Certifications remain on the roadmap
Buyer checklist

What Finance Should Validate Before Switching

The trust review should reduce migration risk, not just satisfy procurement. These are the checks that usually decide whether a move feels safe.
  • Permissions

    Map roles before go-live

    Confirm your approval, reviewer, and external accountant roles map cleanly into NewLedger permissions before go-live.

  • Audit history

    Confirm audit history coverage

    Validate that audit history on journals, invoices, payments, and reconciliations is clear enough for monthly review and year-end support.

  • Trust requirements

    Agree on the evidence you need

    Decide whether your buyer needs residency, DPA, or trust materials before procurement starts instead of late in the cycle.

  • Migration

    Give cutover a clear owner

    Plan who owns migration validation so security and finance both know what must be checked before cutover.

If those answers are still unclear, the right next step is usually a trust and migration review, not a rushed self-serve trial.
Core controls

Current Security Controls

Controls that finance and security reviewers typically ask about first. Availability and coverage vary by plan, feature, and deployment.

Encryption in transit and at rest

Supported Customer Data is encrypted in transit and at rest. Backup placement, encryption, and recovery arrangements depend on the applicable deployment model.

Least-privilege access

Role-based access control limits who can view, create, approve, or post accounting activity. Confirm SSO/SAML availability for your rollout requirements.

Audit-friendly activity history

Supported accounting workflows record actor, timestamp, and change context. Coverage varies by record type and should be validated for your review requirements.

Managed regional infrastructure

NewLedger operates infrastructure in Singapore, Belgium, and Iowa. Supported Customer Data is stored in that infrastructure according to the applicable deployment. Other data and processing may occur elsewhere as described in the Privacy Policy and deployment terms.

Backups and recovery

Encrypted backups and documented restore procedures support recovery. Scope, frequency, retention, and recovery objectives depend on the deployment and applicable agreement.

Monitoring and incident response

Infrastructure and application signals are monitored for abnormal auth, change, and availability patterns. Incidents are handled through a documented response process.

Operating discipline

How We Operate Before Certification

Current engineering, access, and review controls are documented separately from certifications still on the roadmap.
01
Engineering

Secure development practices

  • Production changes go through code review
  • CI checks dependencies and static analysis
  • Privileged access is restricted and audited
  • Secrets are kept out of application source
02
People

Access discipline

  • Workforce screening is applied to relevant roles where permitted by law
  • Relevant teams complete security and privacy training
  • Privileged access is reviewed periodically
  • Standing privileged production access is limited
03
Process

Controls and vendor review

  • Controls are being mapped toward SOC 2 readiness; no Type II report is currently claimed
  • Security testing is risk-based and expands with rollout
  • Incident response runbook is in place
  • Material third-party processors are subject to security review
Data residency

Regional Infrastructure

NewLedger operates infrastructure in Singapore, Belgium, and Iowa. Supported Customer Data is stored in that infrastructure according to the applicable deployment, and is encrypted in transit and at rest. NewLedger maintains a documented disaster recovery plan addressing regional unavailability. Backup, replication, restoration, and any regional recovery capabilities depend on the deployment and any applicable agreement; this statement does not promise automatic failover or uninterrupted service.
APAC
Singapore
EMEA
Belgium
US
Iowa
Responsible disclosure · No monetary rewards

Vulnerability Disclosure Program

We welcome good-faith reports that help us protect NewLedger and our customers. If you believe you have found a security vulnerability, email security@newledger.io. Please read the boundaries below before taking any action.

What to include

Describe the affected service, observed behaviour, potential impact, and the minimum steps needed for us to understand the report. Do not include personal data or confidential customer information in email unless requested through an approved secure channel.

Testing boundaries

This reporting channel does not authorise testing. Do not access another person's account or data, disrupt service, use denial-of-service, social engineering, brute force, automated high-volume scanning, persistence, or destructive techniques. Stop and report immediately if you encounter non-public data.

Disclosure and data handling

Do not retain, copy, share, or publicly disclose non-public data or vulnerability details. Give us a reasonable opportunity to investigate and remediate before any disclosure, and comply with applicable law at all times.

No prize money or financial award

We appreciate responsible reports, but this Vulnerability Disclosure Program is not a bug bounty. NewLedger does not offer prize money, cash rewards, bounties, or any other financial award for reports. Submitting a report does not create any right to payment, compensation, recognition, employment, or commercial engagement. We decide report validity, severity, remediation priority, and any non-monetary recognition at our discretion.

We aim to acknowledge reports within two business days. This is a service target, not a guarantee. These guidelines do not grant permission to violate law, third-party rights, or any agreement, and do not constitute a promise to refrain from legal action.