Security model

Your books stay in Vista.

LedgerLock is built so your IT team's procurement review takes twenty minutes, not three months. One connection, no data residency risk, a full audit trail.

Data retention

Zero data retention.

We do not store transactions, vendors, invoices, GL entries, or balances. The agents query Vista in real time, render the answer, and discard it. No copies, no caches, no training data. The only thing that persists is what you choose to keep: login credentials, your conversation history (deletable anytime), and the audit log.

Audit trail

Every action, logged.

Every match, flag, trace, and post the agent makes is written to an audit log tied to your books. You can see exactly what was done, by which agent, and when, and export the record for your auditor. Nothing happens that you cannot inspect after the fact.

Encryption

Encrypted in transit and at rest.

All data moving between LedgerLock, Vista, and your bank feeds is encrypted in transit. The limited data we retain (credentials and conversation history) is encrypted at rest. We do not claim certifications we do not hold; this page states only what is true today.

Banking

Bank data via Plaid.

Bank and card feeds connect through Plaid, the same infrastructure layer trusted by thousands of financial applications. LedgerLock reads the feed to reconcile against Vista; it never moves money and never initiates a transaction.

Procurement

Need our security questionnaire response?

We keep a standard response ready for procurement and IT review. Email us and we will send it the same day.