Security & responsible disclosure

We take the security of your financial data seriously. If you believe you've found a vulnerability in Ledgers, please tell us — we welcome reports from security researchers and customers.

How to report

Email security@ledgers.work with enough detail to reproduce the issue — affected URL or endpoint, steps, and the impact you observed. If you need to share sensitive proof, say so and we'll arrange a secure channel.

What we ask of you

What you can expect from us

These are commitments, not aspirations. Working days are Monday to Friday excluding England & Wales bank holidays, and the clock starts when your email arrives.

The inbox is read every working day by a named person — our director, who is also our data-protection officer. Ledgers is built by a small team in the UK, so there is no 24/7 security desk, and we'd rather tell you that than imply one. If you believe an issue is being actively exploited, put ACTIVE EXPLOIT in the subject line and we'll treat it as critical from the moment it lands.

Can we actually receive your report?

Yes — and we check, because we once couldn't. Between 9 July and 24 August 2026 this page advertised security@ledgers.work while a misconfigured DNS record meant mail to it bounced. Our outgoing email worked perfectly, so nothing looked wrong from the inside. Every address we publish is now tested end to end, and our build fails if we advertise one without a recorded test proving mail reaches it.

If you reported something in that window, we never received it. Please send it again — we'd genuinely like to hear from you.

In scope

The Ledgers application and the ledgers.work domain. Issues in third-party services we use (e.g. our hosting or bank-data providers) should be reported to those providers; let us know too.

Machine-readable contact details: /.well-known/security.txt