Security

Your data security is our top priority. Learn how we protect your sensitive information.

Security Overview

Ledger L3 is built with security at its core. We understand that you're trusting us with sensitive performance data, private notes, and confidential team information. That's why we've implemented enterprise-grade security measures to ensure your data remains private and protected.

AES-256
Encryption Standard
TLS 1.3
Transport Security
Zero-Knowledge
Architecture

Encryption at Rest

All sensitive data is encrypted before being stored in our database using industry-standard encryption.

AES-256-GCM Encryption

We use AES-256-GCM (Galois/Counter Mode), a NIST-approved encryption algorithm that provides both confidentiality and authenticity. This is the same encryption standard used by governments and financial institutions.

Authenticated Encryption

GCM mode includes authentication tags that verify data integrity, ensuring that encrypted data hasn't been tampered with.

Encrypted Fields

All notes, performance review content, and sensitive employee data are encrypted before storage.

Encryption in Transit

All data transmitted between your browser and our servers is protected using modern encryption protocols.

TLS 1.3 Protocol

We use the latest TLS 1.3 protocol for all connections, ensuring your data is encrypted during transmission.

HTTPS Everywhere

All pages and API endpoints are served over HTTPS. HTTP connections are automatically redirected to HTTPS.

Strong Cipher Suites

We only support modern, secure cipher suites and disable outdated protocols like SSL and TLS 1.0/1.1.

Key Management

Secure key management is critical to maintaining data security.

Secure Key Storage

Encryption keys are stored securely using environment variables and never committed to version control.

Unique Initialization Vectors

Each encrypted value uses a unique, randomly-generated initialization vector (IV) to ensure maximum security.

Key Rotation Ready

Our encryption system is designed to support key rotation as a security best practice.

Database Security

Multiple layers of security protect your data at the database level.

Row Level Security (RLS)

Database policies ensure users can only access their own data. Even if there's a bug in our application code, users cannot access other users' data.

Encrypted Database Storage

Our database provider (Neon) encrypts all data at rest using AES-256 encryption at the infrastructure level.

Secure Connections

All database connections use SSL/TLS encryption and are restricted to authorized application servers only.

Zero-Knowledge Architecture

We've designed Ledger L3 so that we cannot access your private data, even if we wanted to.

Encrypted Before Storage

Your notes and reviews are encrypted on our servers before being saved to the database. We never have access to the plaintext.

No AI Training

Your data is never used to train AI models. When you use AI features, your data is processed only for that specific request and is not retained by AI providers.

You Control Your Data

You can export or delete your data at any time. When you delete data, it's permanently removed from our systems.

Infrastructure & Compliance

We partner with industry-leading providers to ensure your data is secure and available.

Hosting & Infrastructure
  • Vercel: Application hosting with automatic HTTPS and DDoS protection
  • Neon: Serverless PostgreSQL with built-in encryption and backups
Data Privacy
  • GDPR Compliant: We comply with EU data protection regulations
  • Data Residency: Data is stored in secure data centers with SOC 2 compliance
  • Regular Backups: Automated daily backups ensure data durability

Questions about security?

If you have questions about our security practices or would like to report a security concern, please contact us.