What AI is for
Assistance with investigation and explanation of evidence and findings.
Assessment scope and column mapping still require user confirmation.
Evidence enters a controlled workspace before assessment begins. Understand who can act on it and how governed assessment stays separate from AI assistance.
Select a stage to inspect its boundary.
Selecting files on the public homepage does not upload their contents. Entering the application is a separate step, and the files must be selected there for upload.
Keep sensitive details out of public-page questions: the question is passed to the application in the URL.
The application resolves your signed-in session to workspace membership and role. Project and report access are checked against the organisation, with additional permissions for uploads, analysis and administration.
Viewer, Analyst, Admin and Owner have different permissions. The matrix below shows the core actions.
The browser upload flow pseudonymises detected identifier columns. The server checks the received tabular data for supported format, size, completeness and detected direct identifiers. Unsupported formats, oversized or incomplete uploads, and detected raw direct identifiers are rejected before the upload record or file bytes are stored.
Detection has limits. Prepare pseudonymised evidence before upload; automated checks do not guarantee that every personal identifier will be found.
The user confirms the mapping and assessment scope. Governed deterministic controls evaluate the evidence; missing or insufficient evidence cannot be converted into a stronger conclusion.
AI output does not determine regulatory PASS or FAIL.
Reports and evidence are accessed through workspace permissions. A separately created report share link grants read-only access to anyone who has the active link, without requiring a workspace login.
Report share links expire and can be revoked. Treat an active link as access to the report.
Assistance with investigation and explanation of evidence and findings.
Assessment scope and column mapping still require user confirmation.
Permissions are checked in the application. A read-only role cannot upload evidence or start an assessment.
Scroll horizontally to compare all roles →
| Action | Viewer | Analyst | Admin | Owner |
|---|---|---|---|---|
| Read projects and reports | ✓ | ✓ | ✓ | ✓ |
| Upload, confirm mapping and run analysis | — | ✓ | ✓ | ✓ |
| Create and revoke report share links | — | ✓ | ✓ | ✓ |
| Create projects and delete analyses | — | — | ✓ | ✓ |
| Manage team members | — | — | ✓ | ✓ |
| Manage organisation | — | — | — | ✓ |
No. Selection on the homepage keeps the file contents local. Upload happens separately inside the application. Public-page questions are passed in the application URL, so keep sensitive details out of them.
No such guarantee is made. The browser transforms detected identifier columns, and the server rejects detected direct identifiers before storage. Detection has known limits; supply appropriately pseudonymised evidence.
Anyone with the active report link can read it without signing in. Authorised workspace roles can create or revoke links, and links have an expiry.
Contact LedgerProof before onboarding to confirm deployment-specific hosting, retention, deletion, subprocessors and incident-response arrangements. This page describes application controls; it is not a security certification or a deployment-specific assurance report.
Discuss data handling →