Security & responsible disclosure
We take the security of your financial data seriously. If you believe you've found a vulnerability in Ledgers, please tell us — we welcome reports from security researchers and customers.
How to report
Email security@ledgers.work with enough detail to reproduce the issue — affected URL or endpoint, steps, and the impact you observed. If you need to share sensitive proof, say so and we'll arrange a secure channel.
What we ask of you
- Give us a reasonable chance to investigate and fix the issue before disclosing it publicly.
- Don't access, modify, or delete data that isn't yours — use only test accounts/data.
- Don't run attacks that degrade the service (no DoS, spam, or social engineering of our staff or users).
- Don't violate anyone's privacy.
What you can expect from us
- We'll acknowledge your report within 3 working days.
- We'll keep you updated on our assessment and remediation.
- We won't pursue legal action against good-faith research that follows this policy (safe harbour).
In scope
The Ledgers application and the ledgers.work domain. Issues in third-party services we use (e.g. our hosting or bank-data providers) should be reported to those providers; let us know too.
Machine-readable contact details: /.well-known/security.txt