Encryption
All traffic to and from LedgerDue is encrypted in transit using TLS. Data is encrypted at rest by our infrastructure providers.
Authentication & access
We offer strong, modern sign-in options so you can protect your account the way that suits you:
- Passwords are never stored in plain text — they are salted and hashed.
- Passkeys and biometric sign-in are supported on compatible devices.
- Optional two-factor authentication by email code.
- An optional recovery email so you can regain access if you lose your primary credentials.
Hosting & infrastructure
LedgerDue runs on established, security-conscious cloud infrastructure. Application hosting is provided by Vercel and our database and authentication are managed by Supabase, both of which maintain their own robust security and compliance programmes.
Payments
We do not store your card details. All payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider.
Backups & availability
Your data is securely backed up by our infrastructure providers to ensure resilience and recovery in the event of a system failure. We continuously monitor the service to keep it reliable and performant.
Data protection
We handle personal data in line with UK data protection law. For the client information you enter, your practice is the data controller and LedgerDue acts as your processor. See our Privacy Notice and Data Processing Addendum for the detail.
Responsible disclosure
If you believe you have found a security vulnerability, please let us know right away at contact@ledgerdue.uk We welcome responsible disclosure and will work with you to investigate and resolve genuine issues promptly.