Ledgerbrook / Security
Security and client data
You are considering handing an outside practice access to your clients' financial records. This page is the whole answer to what that means: what we can see, what we hold, what we have signed, and how you end it. Your clients' books stay under your control throughout, and most of what follows you can verify from inside the client's own QuickBooks account rather than taking our word for it.
No badges
What we don't claim
Ledgerbrook holds no SOC 2 report, no ISO 27001 certificate and no third-party security audit. A small practice that claimed one would be either lying or quoting somebody else's — usually the cloud provider's — and both are easy to check.
If your firm's own policy requires a certified subcontractor, this is the line to rule us out on, and we would rather you found it here than three emails in. What we offer instead is an access model narrow enough that the certification would be describing a smaller surface than you might expect.
Access
What we can actually see
Accountant-level access to the QuickBooks Online company, and nothing beyond it. That is enough to categorize transactions, reconcile accounts and run reports. It is not enough to touch the client's billing or subscription, and not enough to delete the company file. The role appears in the client's own user list, which is also where you revoke it — at any time, without asking us, and without our cooperation.
Where a file needs a bank statement or a prior return that is not in QuickBooks, it comes through whatever document system your firm already uses. We do not ask a firm to adopt a portal of ours, because we do not run one.
Records
We don't keep a copy of your clients' records
Working papers, the flagged-items list and every document a file needs live in the client's own QuickBooks company or in a folder your firm controls. There is no parallel archive of your client list on our side, which has a consequence worth stating plainly: at the end of an engagement there is nothing of yours for us to return or delete, because it was never held separately in the first place.
The exception is ordinary correspondence. Email between your firm and ours is email, and it persists in both mailboxes like any other business record. If a thread would contain something that should not sit in an inbox, put it in the file or the folder and point us at it.
Confidentiality
Whose paperwork governs it
Yours. We sign your firm's NDA and your firm's subcontractor terms rather than asking you to sign ours. Your client's engagement is with your firm alone; ours is with your firm, and your client is never asked to agree to anything of ours.
Non-solicitation runs alongside it and is the term firms ask about most: a business you introduce is your client permanently. We don't market to them and we won't accept a direct engagement from them, including after your firm's own relationship with them ends. That is set out in full on the bookkeeping-firm page, and there is a checklist of the seven things worth reading in any subcontractor agreement — ours included — on the agreement page.
Working practice
How the work is actually done
The unglamorous half, and the half a questionnaire asks about. None of it is remarkable; the point is that it is stated rather than assumed.
We do not pass your files to a third party. If that ever needed to change for a particular engagement, your firm would be asked first and would be free to say no.
If something goes wrong
What happens if there's an incident
You hear about it from us, the same day we know, in writing, before we have finished working out how bad it is. That covers a credential we think may be exposed, a device lost, a mistaken disclosure, or anything else touching a file of yours — and it holds whether or not we think your client was actually affected.
The reason to promise it in this direction is that your firm, not ours, owns the relationship with the client and any notification duty that follows. Telling you late would take that decision out of your hands, which is a worse failure than the incident usually is.
Retention
When an engagement ends
You remove the accountant user from the client's QuickBooks file, and that is the whole offboarding. Because the records were never held separately, there is no export to request and no deletion certificate to chase. Any working documents sitting in a folder your firm controls stay exactly where they are — under your control, as they were throughout.
What we keep afterwards is the correspondence and our own invoices to your firm, which is the same record any business keeps of who it has worked for.
This site
What ledgerbrook.com itself collects
Separate question, separate page, and a much shorter answer: the privacy page says what this website collects and what it doesn't. No client data is ever sent through this site, and the contact form on the contact page is for reaching us, not for sending records — never attach a client's documents to it.
Diligence
Ask us anything this page missed
If your firm has a vendor questionnaire, send it. A straight answer to it, including the questions where the answer is "no, we don't have that", comes back faster than a sales call would. The free file review also works as its own diligence exercise: read-only accountant access on one file, and you get to watch how we handle it before anything larger is agreed.
Accountant-level access, no card. Or write to omkar@ledgerbrook.com directly.