Skip to content
LedgerProof
Security

Clear boundaries.
Controlled access.

Evidence enters a controlled workspace before assessment begins. Understand who can act on it and how governed assessment stays separate from AI assistance.

The path your evidence takes.

Select a stage to inspect its boundary.

01 · Public site

Choose files locally. Upload inside the application.

Selecting files on the public homepage does not upload their contents. Entering the application is a separate step, and the files must be selected there for upload.

Keep sensitive details out of public-page questions: the question is passed to the application in the URL.

AI boundary

Assistance with investigation.
Authority stays with governed tests.

01 · Assistive role

What AI is for

Assistance with investigation and explanation of evidence and findings.

Assessment scope and column mapping still require user confirmation.

02 · Governed boundary

What AI does not do

  • Determine a regulatory PASS or FAIL.
  • Fill missing evidence with inferred facts.
  • Approve new regulatory semantics or thresholds.
Workspace roles

The right actions for each role.

Permissions are checked in the application. A read-only role cannot upload evidence or start an assessment.

Scroll horizontally to compare all roles →

Core permissions by workspace role
ActionViewerAnalystAdminOwner
Read projects and reports✓✓✓✓
Upload, confirm mapping and run analysis—✓✓✓
Create and revoke report share links—✓✓✓
Create projects and delete analyses——✓✓
Manage team members——✓✓
Manage organisation———✓
Evidence handling

Know what crosses the boundary.

Are files uploaded from the public homepage?

No. Selection on the homepage keeps the file contents local. Upload happens separately inside the application. Public-page questions are passed in the application URL, so keep sensitive details out of them.

Does pseudonymisation remove every identifier?

No such guarantee is made. The browser transforms detected identifier columns, and the server rejects detected direct identifiers before storage. Detection has known limits; supply appropriately pseudonymised evidence.

Who can open a shared report?

Anyone with the active report link can read it without signing in. Authorised workspace roles can create or revoke links, and links have an expiry.

Where can I confirm hosting and retention terms?

Contact LedgerProof before onboarding to confirm deployment-specific hosting, retention, deletion, subprocessors and incident-response arrangements. This page describes application controls; it is not a security certification or a deployment-specific assurance report.

Discuss data handling →