Trust & Security Center

Your books are yours — and we protect them.

Valinor Ledger is built for the people who run a business's money. Here is exactly how we keep your financial data secure, backed up, portable, and private.

Last updated

Encryption

Data is encrypted both while moving across the network and while sitting in our systems.

In transit
All traffic is served exclusively over TLS 1.2+ (HTTPS). HSTS is enforced so browsers never downgrade to plaintext.
At rest
The database and file storage are encrypted at rest with AES-256. Sensitive application secrets — bank tokens and MFA seeds — are additionally encrypted at the application layer with AES-256-GCM before they ever reach the database.
Tenant isolation
Every table enforces PostgreSQL Row-Level Security scoped to your company, with a defense-in-depth application filter on top. One tenant can never read another tenant's data.

Backups & data portability

We keep redundant, encrypted backups — and you can always take a full copy of your data with you.

Continuous (Point-in-Time Recovery)
Database writes are continuously backed up, enabling point-in-time recovery to any moment within the retention window.
Daily snapshots
Full automated snapshots are taken daily and retained for 7 days (longer on higher tiers). Snapshots are encrypted and stored redundantly.
Your own export
You can export 100% of your books at any time — every ledger, invoice, bill, and journal entry — as a CSV/JSON archive. Your data is portable by design; you are never locked in.

Authentication & two-factor (MFA)

Strong account security is built in. Turn on two-factor authentication in your account settings in under a minute.

TOTP two-factor authentication
Enroll any standard authenticator app (Google Authenticator, 1Password, Authy) via QR code. Once enabled, a one-time code is required at every sign-in — a stolen password alone is not enough.
Single-use backup codes
Enrollment issues ten single-use recovery codes so you never lose access if your device is unavailable. Codes are stored only as irreversible hashes.
Brute-force protection
Sign-in and second-factor attempts are rate-limited per account and source. Repeated failures are throttled to defeat guessing attacks.
Role-based access control
Owner, admin, accountant, user, and viewer roles gate every sensitive action. Administrative operations and data export are restricted to owners and admins.

Sub-processors

We use a small set of trusted infrastructure providers to deliver the service. Each is bound by data-protection terms.

ProviderPurposeLocation
Supabase (PostgreSQL + Storage + Auth)Primary database, file storage, and authenticationUnited States (AWS us-east)
VercelApplication hosting and global edge networkUnited States / global edge
Anthropic (Claude)AI assistant, insights, narration, document understanding and background title enrichment, only after a company administrator enables AI processingUnited States
Voyage AIOptional semantic search embeddings of company knowledge, only after a company administrator enables AI processingUnited States
PlaidBank account connections and transaction sync (opt-in)United States
StripeSubscription billing and payment processing (opt-in)United States

Incident response policy

If something goes wrong, we have a clear plan to detect, contain, and tell you about it.

Detection & monitoring
Application and database activity is logged and monitored. A tamper-evident audit log records sensitive actions across the system.
Response
Confirmed security incidents are triaged and contained by the engineering team on a 24/7 basis, with eradication and recovery steps tracked to closure.
Notification
If an incident affects your data, we will notify affected customers without undue delay (and within 72 hours where required by law), including what happened, the impact, and the remediation taken.
Report a concern
Found a vulnerability or have a security question? Email security@financeflow.app. To report an active incident, email incident@financeflow.app.

Have a security question?

Procurement, due-diligence, or a security review — we're happy to help. You can also manage two-factor authentication and export your data from your account.