Safety & soundness

What your examiners will ask. What we answer.

This page is written for a bank board, not a security conference. Every claim below is demonstrated in the product — ask us to show you any of them in the live demo.

01Read-only aggregation by default

LEDGERLINK reads balances and transactions. It does not move money. Payments happen only inside the bank’s own rails — the same core, the same approval chains — with dual approval enforced on wires over $50,000 and callback verification on any new beneficiary.

02Encryption in transit and at rest

All connections use TLS 1.2+. All stored data is encrypted at rest. There is no unencrypted path between a source system and the LEDGERLINK database.

03Per-bank AND per-customer isolation

Row-level security is enforced at two levels in the database itself — not in application code. Bank A cannot see Bank B’s data, and within a bank, Hetzel Holdings cannot see another customer’s data. Every query carries both tenant and organization scope, and the database rejects anything else.

04Credentials never stored for file-based sources

File bridges (lockbox, armored carrier, return files) authenticate with SFTP key exchange. There are no stored passwords for those systems anywhere in LEDGERLINK.

05Hash-chained audit log

Every material action — an issue file loaded, an exception decided, a user added — is written to an append-only log where each event stores the hash of the previous one. Tampering breaks the chain visibly. The log exports as evidence for examiners.

06MFA mandatory

Every user authenticates with a second factor. Passkeys for owners and controllers; TOTP minimum for all other roles. There is no MFA opt-out.

07SOC 2 Type II path

Type I readiness assessment complete Q3 2026. Type I report targeted Q4 2026. Type II observation window opens Q1 2027 with report targeted Q3 2027.

08Deployment options

Hosted single-tenant by default. On-premises or bank-managed cloud available for institutions whose examiners require it. The bank owns its data in every model — exportable in full, on demand.

The safe failure mode

If a customer never logs in, never decides, never lifts a finger — the suspicious check still returns automatically at the 2:00 PM cutoff. LEDGERLINK is designed so that doing nothing is always the safe outcome.