Security and Compliance Controls
What Finance Should Validate Before Switching
Permissions
Map roles before go-live
Confirm your approval, reviewer, and external accountant roles map cleanly into NewLedger permissions before go-live.
Audit history
Confirm audit history coverage
Validate that audit history on journals, invoices, payments, and reconciliations is clear enough for monthly review and year-end support.
Trust requirements
Agree on the evidence you need
Decide whether your buyer needs residency, DPA, or trust materials before procurement starts instead of late in the cycle.
Migration
Give cutover a clear owner
Plan who owns migration validation so security and finance both know what must be checked before cutover.
Policies, docs, and support
Privacy Policy
How we handle personal data
Learn moreFAQ
Pricing, trial, and rollout answers
Learn moreAPI documentation
Integration and auth patterns
Learn morePlatform architecture
Tenant boundaries and platform model
Learn moreDeployment options
Managed cloud and qualifying BYOC
Learn moreContact us
Security review or trust questions
Learn moreCurrent Security Controls
Encryption in transit and at rest
Supported Customer Data is encrypted in transit and at rest. Backup placement, encryption, and recovery arrangements depend on the applicable deployment model.
Least-privilege access
Role-based access control limits who can view, create, approve, or post accounting activity. Confirm SSO/SAML availability for your rollout requirements.
Audit-friendly activity history
Supported accounting workflows record actor, timestamp, and change context. Coverage varies by record type and should be validated for your review requirements.
Managed regional infrastructure
NewLedger operates infrastructure in Singapore, Belgium, and Iowa. Supported Customer Data is stored in that infrastructure according to the applicable deployment. Other data and processing may occur elsewhere as described in the Privacy Policy and deployment terms.
Backups and recovery
Encrypted backups and documented restore procedures support recovery. Scope, frequency, retention, and recovery objectives depend on the deployment and applicable agreement.
Monitoring and incident response
Infrastructure and application signals are monitored for abnormal auth, change, and availability patterns. Incidents are handled through a documented response process.
How We Operate Before Certification
Secure development practices
- Production changes go through code review
- CI checks dependencies and static analysis
- Privileged access is restricted and audited
- Secrets are kept out of application source
Access discipline
- Workforce screening is applied to relevant roles where permitted by law
- Relevant teams complete security and privacy training
- Privileged access is reviewed periodically
- Standing privileged production access is limited
Controls and vendor review
- Controls are being mapped toward SOC 2 readiness; no Type II report is currently claimed
- Security testing is risk-based and expands with rollout
- Incident response runbook is in place
- Material third-party processors are subject to security review
Regional Infrastructure
Vulnerability Disclosure Program
What to include
Describe the affected service, observed behaviour, potential impact, and the minimum steps needed for us to understand the report. Do not include personal data or confidential customer information in email unless requested through an approved secure channel.
Testing boundaries
This reporting channel does not authorise testing. Do not access another person's account or data, disrupt service, use denial-of-service, social engineering, brute force, automated high-volume scanning, persistence, or destructive techniques. Stop and report immediately if you encounter non-public data.
Disclosure and data handling
Do not retain, copy, share, or publicly disclose non-public data or vulnerability details. Give us a reasonable opportunity to investigate and remediate before any disclosure, and comply with applicable law at all times.
No prize money or financial award
We appreciate responsible reports, but this Vulnerability Disclosure Program is not a bug bounty. NewLedger does not offer prize money, cash rewards, bounties, or any other financial award for reports. Submitting a report does not create any right to payment, compensation, recognition, employment, or commercial engagement. We decide report validity, severity, remediation priority, and any non-monetary recognition at our discretion.
We aim to acknowledge reports within two business days. This is a service target, not a guarantee. These guidelines do not grant permission to violate law, third-party rights, or any agreement, and do not constitute a promise to refrain from legal action.