Security and Trust Center
Last updated: October 5, 2026
DeepLedger works inside your books, so we hold ourselves to the standard you hold your ledger to. This page explains how your data is protected, how the AI agent is kept in check, who helps us run the service, and how retention and deletion work. For the legal terms, see our Privacy Policy and Terms of Service.
Encrypted everywhere
TLS in transit, encrypted at rest, and QuickBooks tokens encrypted again by us.
Isolated by company
Database rules keep each company's data visible only to the people you give access.
You decide the unclear ones
The AI agent records only what it is sure of. Anything else becomes a task for your review.
Every AI action logged
Each tool call the AI agent makes is recorded and visible in your activity feed.
Deletion on request
Ask from Settings and we delete your data within 30 days.
1. How your data is protected
- All traffic to DeepLedger, the MCP server and our providers is encrypted in transit with TLS (HTTPS).
- Data is encrypted at rest by our database and storage provider.
- QuickBooks access tokens are additionally encrypted by DeepLedger with AES-256-GCM before they are stored, and are never shared with third parties.
- API keys you create are stored only as SHA-256 hashes. We show a key once, when you create it, and cannot show it again.
- Bank connection credentials are held by the bank connection provider; the few secrets we keep are readable only by our backend, never by a signed-in user.
- We never receive or store card numbers. Stripe processes payments.
2. Who can see what
- Row-level security in our database keeps every company's records separate. A request can only read rows of companies its user has been given access to.
- Owners and admins see every company in the workspace. Other team members see only the companies an owner or admin assigns to them.
- DeepLedger reaches QuickBooks only through the access you grant on Intuit's own sign-in screen. You can disconnect a company at any time from Settings or from QuickBooks.
3. How the AI agent works with your books
- The AI agent records a transaction only when the payee, account and amount are clear from the evidence. Anything uncertain becomes a task for you to review, and it records nothing on those until you decide.
- The tools check every write before it reaches QuickBooks and refuse entries QuickBooks would accept but get wrong. The agent's recording procedure includes a duplicate check against your existing entries.
- Every tool call the AI agent makes, read or write, is recorded with its result and shown in your activity feed.
- Scheduled routines run read-only: they can report on your books but never change them.
- DeepLedger does not train AI models on your data. The AI agent in the portal is powered by Anthropic, which processes requests under its commercial terms. If you connect your own AI app instead, data the tools return goes to that app's provider under its terms; review its retention settings before you connect it.
4. Service providers
These companies process data on our behalf to run DeepLedger. Each maintains its own security program; follow the links for their attestations and documentation.
| Provider | What it does for DeepLedger |
|---|---|
| Supabase | Database, sign-in and file storage (United States) |
| Render | Application hosting (United States) |
| Anthropic | AI processing for the AI agent in the DeepLedger portal |
| Intuit QuickBooks Online | Your accounting system of record, reached only with the access you grant |
| Stripe | Subscription payments, and bank connections for US banks (Stripe Financial Connections) |
| Plaid | Bank connections where enabled |
| Resend | Account, billing, security and report emails |
5. Data retention and deletion
- While your subscription is active, we keep your workspace data so the service can work.
- After your subscription ends, we delete your workspace data 30 days after your paid service ends: uploaded documents, bank feed lines, tasks, cached QuickBooks data, AI memory, AI chats, activity logs and preferences.
- Whenever you ask. Request deletion of your personal account, or (as an owner or admin) of the whole workspace, from Settings › Account › Delete your data, or by emailing hello@deepledger.ai. We confirm the request by email, complete it within 30 days, and tell you when it is done.
- What deletion does not touch: your records in QuickBooks Online, which DeepLedger never deletes; billing, payment and legal records we must keep; backups until their retention cycle ends; and copies held by AI apps or other services you connected, which you request from them.
Export anything you want to keep before deletion. The full rules are in section 7 of our Privacy Policy.
6. Report a security issue or ask a question
If you believe you have found a vulnerability, email hello@deepledger.ai with "Security" in the subject. Please give us a reasonable chance to fix it before sharing it publicly, and do not access other customers' data while testing. The same address takes security questionnaires and questions about how we handle your data.