Data protection
- All traffic to and from Hate Ledger is encrypted with TLS 1.2 or higher.
- Application data at rest is encrypted with AES-256 on managed cloud storage.
- Every row of your financial data is scoped to your user via row-level security policies.
Access controls
- Least-privilege access to production systems for our team.
- Passwords hashed with industry-standard algorithms; leaked-password checks on signup and change.
- Sensitive operations (deletes, exports, admin actions) are recorded in an internal audit log.
Payments
Hate Ledger does not store card numbers. Payments are processed by Stripe, which is PCI-DSS Level 1 certified. For subscriptions on eligible plans, taxes, fraud protection, and dispute handling are managed on your behalf for buyers in approximately 80 supported countries.
Availability and backups
Managed database backups run daily with 7-day retention. Static assets are served from a global edge network.
Vulnerability reporting
Found something? Email services@hateledger.com with reproduction steps. We respond within one business day and coordinate disclosure. We do not pursue security researchers acting in good faith.
Shared responsibility
We secure the platform. You are responsible for keeping your login credentials safe, reviewing team-member access, and enabling two-factor authentication when it becomes available on your plan.
This page is app-owned editable content maintained by Hate Ledger to answer common questions about the service. It is not an independent certification. For anything binding or company-specific, email services@hateledger.com.