Security & responsible disclosure
We take the security of your financial data seriously. If you believe you've found a vulnerability in Ledgers, please tell us — we welcome reports from security researchers and customers.
How to report
Email security@ledgers.work with enough detail to reproduce the issue — affected URL or endpoint, steps, and the impact you observed. If you need to share sensitive proof, say so and we'll arrange a secure channel.
What we ask of you
- Give us a reasonable chance to investigate and fix the issue before disclosing it publicly.
- Don't access, modify, or delete data that isn't yours — use only test accounts/data.
- Don't run attacks that degrade the service (no DoS, spam, or social engineering of our staff or users).
- Don't violate anyone's privacy.
What you can expect from us
These are commitments, not aspirations. Working days are Monday to Friday excluding England & Wales bank holidays, and the clock starts when your email arrives.
- Acknowledgement within 3 working days. A human reply confirming we have your report — not an autoresponder. If you don't hear from us in that time, assume something went wrong and chase us.
- Assessment within 10 working days. We'll tell you whether we've reproduced the issue, what severity we've assigned it and why, and our intended fix timeline. If we disagree that it's a vulnerability, we'll say so and explain our reasoning rather than going quiet.
- Updates at least every 10 working days while the report is open, even when the update is only that work is still in progress.
- Fix targets from the day we confirm the issue: critical 7 days, high 30 days, medium 90 days, low on a best-effort basis. If we're going to miss one, you'll hear it from us before the deadline, with a revised date.
- We'll confirm when it's fixed, and credit you by name or handle if you'd like — just tell us how you want to be named.
- We won't pursue legal action against good-faith research that follows this policy (safe harbour).
The inbox is read every working day by a named person — our director, who is also our data-protection officer. Ledgers is built by a small team in the UK, so there is no 24/7 security desk, and we'd rather tell you that than imply one. If you believe an issue is being actively exploited, put ACTIVE EXPLOIT in the subject line and we'll treat it as critical from the moment it lands.
Can we actually receive your report?
Yes — and we check, because we once couldn't. Between 9 July and 24 August 2026 this page advertised security@ledgers.work while a misconfigured DNS record meant mail to it bounced. Our outgoing email worked perfectly, so nothing looked wrong from the inside. Every address we publish is now tested end to end, and our build fails if we advertise one without a recorded test proving mail reaches it.
If you reported something in that window, we never received it. Please send it again — we'd genuinely like to hear from you.
In scope
The Ledgers application and the ledgers.work domain. Issues in third-party services we use (e.g. our hosting or bank-data providers) should be reported to those providers; let us know too.
Machine-readable contact details: /.well-known/security.txt