Skip to main content

Trust & Security

Regulated by design. Transparent about what is live today.

Ledger Lens is built for a regulated sector. Every posture below is either in place today, or clearly listed as roadmap so nothing on this page overclaims.

UK GDPR

In place

Aligned with UK GDPR. Data residency in the European Union. A standard Data Processing Agreement is available on request.

ICAEW Technology Code of Ethics

In place

Designed to align with the ICAEW Technology Code of Ethics, respectful of the regulated professional context of our users.

Encryption

In place

TLS 1.2+ in transit; AES-256 at rest for uploaded filings, tokens and application secrets.

Hosting

In place

Hosted on managed European infrastructure with row-level security on every application table.

HMRC transparency

In place

The enquiry-risk model uses only publicly available HMRC enforcement disclosures — no confidential HMRC data.

SOC 2 Type II

On roadmap

On our security roadmap. We are not claiming a SOC 2 attestation today; audit scoping covers security, availability, confidentiality and processing integrity.

ISO 27001

On roadmap

On our security roadmap. We are not claiming ISO 27001 certification today; the ISMS is being scoped across the platform and supporting infrastructure.

Independent certifications such as SOC 2 Type II and ISO 27001 are on our security roadmap; we do not claim either today. A standard Data Processing Agreement, subprocessor list and security summary are available on request from privacy@myledgerlens.co.uk.