Safety & soundness
What your examiners will ask. What we answer.
This page is written for a bank board, not a security conference. Every claim below is demonstrated in the product — ask us to show you any of them in the live demo.
01Read-only aggregation by default
LEDGERLINK reads balances and transactions. It does not move money. Payments happen only inside the bank’s own rails — the same core, the same approval chains — with dual approval enforced on wires over $50,000 and callback verification on any new beneficiary.
02Encryption in transit and at rest
All connections use TLS 1.2+. All stored data is encrypted at rest. There is no unencrypted path between a source system and the LEDGERLINK database.
03Per-bank AND per-customer isolation
Row-level security is enforced at two levels in the database itself — not in application code. Bank A cannot see Bank B’s data, and within a bank, Hetzel Holdings cannot see another customer’s data. Every query carries both tenant and organization scope, and the database rejects anything else.
04Credentials never stored for file-based sources
File bridges (lockbox, armored carrier, return files) authenticate with SFTP key exchange. There are no stored passwords for those systems anywhere in LEDGERLINK.
05Hash-chained audit log
Every material action — an issue file loaded, an exception decided, a user added — is written to an append-only log where each event stores the hash of the previous one. Tampering breaks the chain visibly. The log exports as evidence for examiners.
06MFA mandatory
Every user authenticates with a second factor. Passkeys for owners and controllers; TOTP minimum for all other roles. There is no MFA opt-out.
07SOC 2 Type II path
Type I readiness assessment complete Q3 2026. Type I report targeted Q4 2026. Type II observation window opens Q1 2027 with report targeted Q3 2027.
08Deployment options
Hosted single-tenant by default. On-premises or bank-managed cloud available for institutions whose examiners require it. The bank owns its data in every model — exportable in full, on demand.
The safe failure mode
If a customer never logs in, never decides, never lifts a finger — the suspicious check still returns automatically at the 2:00 PM cutoff. LEDGERLINK is designed so that doing nothing is always the safe outcome.
