Security

What we actually do to protect the little information we hold.

  1. 1

    You choose a document

    Only what the review requires

  2. 2

    It is read for analysis

    Spreadsheets in your browser

  3. 3

    Findings are produced

    Deterministic calculations

  4. 4

    You delete it

    Storage and records, in one action

Encryption

All traffic runs over HTTPS. Records and saved files are held on the managed cloud platform's encrypted storage infrastructure. FixLedger does not add its own field-level encryption, so we do not claim more than the platform provides.

Per-account isolation

Every accounting review, source document, finding, and activity record is tied to your account. Access controls prevent one customer account from retrieving another account's records.

Private file storage

Saved documents live in a private bucket under a folder keyed to your account. There are no public links, and files cannot be listed or read by another account.

Analyze-only by default

Spreadsheets are parsed in your browser. A PDF or image you choose is sent securely for temporary text extraction, then discarded without being saved unless you choose Save to workspace.

No AI training on your data

Two steps use a hosted model, both through the platform's AI gateway, which does not use application data for model training. Extraction sends only the single PDF or image you selected. The written explanation sends only balances, finding titles, amounts, confidence figures and signal words — no files and no transaction rows. Nothing is written to a model provider's account or stored by FixLedger during either step.

When data disappears

An analyze-only file is never stored: it exists only for the length of the request. A saved review keeps its figures and, if you chose it, the file, until you delete it. Deleting a review removes its file and every related record in the same action. Deleted rows also age out of the platform's rolling automated database backups, which are retained for about 14 days.

Server-side keys

API keys for the explanation service are held on the server and never exposed to the browser.

Retention and deletion

Nothing is retained unless you choose Save to workspace. The Privacy & data screen shows what is stored and permanently deletes it from file storage and account records.

Administrative access

The internal administrative view shows counts and activity dates only. Database access rules grant no administrator any route to another account's documents, transactions or findings — an administrator reading them would have to be granted new database access first.

Logs

Application logs record errors and request activity, not document contents or transaction rows. Activity records held in your workspace store the action taken and identifiers only.

Honest limits

No service can promise data will never be breached. That is precisely why FixLedger asks for the minimum, stores as little as possible, and lets you delete it in one action.

Sub-processors: cloud hosting and managed database/storage for the application, and a hosted model provider used for temporary PDF/image extraction and the plain-language explanation step.