security
what we run
ledgerpost is a manual ledger — you type in your own transactions. we don't connect to your bank, we don't move money, and we don't hold funds. postgres and redis, hosted in germany. passwords are hashed, never stored in the clear. api keys and login tokens are hashed too. two-factor secrets are encrypted. we hash and truncate ip addresses before we ever write one down — we don't keep raw ip addresses anywhere.
found a problem?
email ledger.post@outlook.com with what you found and how to reproduce it. include enough detail that we can verify it without guessing. we read this inbox and we'll get back to you within 2 business days.
what we ask
- give us a reasonable window to fix something before writing about it publicly
- don't access, modify, or delete data that isn't yours while testing
- don't run anything that could degrade the service for other users (no load testing against production, no automated scanning without asking first)
what we commit to
- we'll acknowledge your report within 2 business days
- we'll tell you when it's fixed
- we're a small team without a bug bounty budget right now, but we'll say thanks publicly if you want the credit, and we won't go after you for a good-faith report that follows the above