Trust & Security
Regulated by design. Transparent about what is live today.
Ledger Lens is built for a regulated sector. Every posture below is either in place today, or clearly listed as roadmap so nothing on this page overclaims.
UK GDPR
In placeAligned with UK GDPR. Data residency in the European Union. A standard Data Processing Agreement is available on request.
ICAEW Technology Code of Ethics
In placeDesigned to align with the ICAEW Technology Code of Ethics, respectful of the regulated professional context of our users.
Encryption
In placeTLS 1.2+ in transit; AES-256 at rest for uploaded filings, tokens and application secrets.
Hosting
In placeHosted on managed European infrastructure with row-level security on every application table.
HMRC transparency
In placeThe enquiry-risk model uses only publicly available HMRC enforcement disclosures — no confidential HMRC data.
SOC 2 Type II
On roadmapOn our security roadmap. We are not claiming a SOC 2 attestation today; audit scoping covers security, availability, confidentiality and processing integrity.
ISO 27001
On roadmapOn our security roadmap. We are not claiming ISO 27001 certification today; the ISMS is being scoped across the platform and supporting infrastructure.
Independent certifications such as SOC 2 Type II and ISO 27001 are on our security roadmap; we do not claim either today. A standard Data Processing Agreement, subprocessor list and security summary are available on request from privacy@myledgerlens.co.uk.