---
title: "How we protect your financial data"
description: "How LedgerBPO protects financial data: least-privilege access, MFA, encryption, background-checked staff, HIPAA-trained agents, DPAs."
url: https://ledgerbpo.com/security/
updated: 2026-09-11
publisher: LedgerBPO (SS Support Network LLC)
language: en-US
---

# How we protect your financial data

Accounting outsourcing security at LedgerBPO rests on one rule: we can see, post and reconcile, but we cannot move your money. Access runs through your software’s accountant role and read-only bank feeds, every login uses MFA, access is logged per client, staff are background-checked and work on managed devices with no local downloads. Certifications are listed only when held.

- We never move money
- MFA on every login
- Access logs per client
- Certifications only when held

Updated September 2026

## We never move money

You approve and release every payment. We prepare payment runs in Bill.com, Melio, Plooto or your bank portal for your release, and we never hold online-banking credentials that can transfer funds.

## Least-privilege access

Accountant or advisor roles in QuickBooks Online, Xero, Zoho, Sage and the tools the work touches. Access is granted per person, reviewed quarterly and revoked on the last day of an engagement.

## MFA everywhere

Multi-factor authentication is required on every account our staff use, including your software, our portal and email. Shared logins are not permitted.

## Access logs per client

Every login and change in your file is attributable to a named person. We keep an access log per client and review it on request.

## Managed devices, no paper

Staff work on managed devices with disk encryption, no local downloads and no printing. Clean-desk and no-personal-device rules are enforced in both offices.

## People

Background checks before hire, an NDA per client, security training at onboarding and annually, and HIPAA training for anyone touching patient data.

## Data in transit and at rest

Encrypted in transit (TLS) and at rest in the cloud tools we and you use. Client documents live in your software or the LedgerDesk portal, not in inboxes.

## Incident response

A written incident-response plan with named owners, client notification within 72 hours of us becoming aware of an incident affecting your data (sooner where your DPA says so), and a post-incident review.

## Written security plan

A written information security program covering the FTC Safeguards Rule elements for US tax data: risk assessment, access controls, encryption, MFA, training and vendor oversight.

Country-specific rules (IRS section 7216, FTC Safeguards, UK GDPR, PIPEDA, Australian Privacy Act, HIPAA) are on the [compliance page](https://ledgerbpo.com/compliance/). The processor terms are summarised in the [data processing agreement](https://ledgerbpo.com/dpa/). Report a vulnerability at [security.txt](https://ledgerbpo.com/.well-known/security.txt).

## Frequently asked questions

### Are you SOC 2 or ISO 27001 certified?

We list certifications only when held. The controls above are in place today; a third-party attestation is on the roadmap and will appear on this page when it is issued, with the report available under NDA. Until then, we do not use the badges.

### Can your staff see my bank account?

Read-only, through the feed inside your accounting software, where your bank supports it. That view shows transactions and balances and cannot initiate transfers. Where a read-only feed is not available we work from statements you share.

### Where is my data processed?

In the cloud tools you already use, by SS Support Network staff in the United States and at our second office in Pakistan. Transfer safeguards for UK, EU, Canadian and Australian clients are set out in the data-processing agreement.

### Do you sign a BAA for healthcare clients?

Yes. US healthcare clients receive a business associate agreement, staff who touch patient data are HIPAA-trained, and access to protected health information is limited to the billing team assigned to you.

### What happens to my data when we stop?

Our access is revoked on the last day. Your software, files and documents were always in your accounts, so there is nothing to migrate. Working papers we hold are returned or deleted per the DPA.

### Can I audit you?

Yes. Clients and their auditors can request the access log for their file, the security policy summary and, when available, the third-party attestation report under NDA.

Next step

## Books closed. Invoices paid. Every month.

Tell us what is going on with your books or billing. You will hear from a named person within 1 business day, with a custom quote and a plan for the first close.

- Reply from a named person within 1 business day
- No setup fee, month-to-month
- Your software, your data, no lock-in

Start with a custom quote

[Get a custom quote](https://ledgerbpo.com/get-a-quote/) [Book a 20-minute call](https://ledgerbpo.com/book-a-call/) Or call [+1-657-777-0006](tel:+16577770006) during US, UK or Australian business hours.

---

Source: https://ledgerbpo.com/security/ · Contact: https://ledgerbpo.com/contact/ · Full site map for agents: https://ledgerbpo.com/llms.txt
