You are handing us a key to your payment data. Here is exactly what it opens.
Short version: we can read, we cannot touch, and you can cut us off from inside Stripe at any moment.
Read-only, and verified before we keep it
Ledgerwide runs on a Stripe restricted key. The setup guide lists the seven read permissions we need and nothing else; the key is tested against each one before it is stored, and refused if any is missing. There is no code path that creates a charge, a refund, a payout or a setting change.
Keys encrypted at rest, decrypted only in the background
Your key is envelope-encrypted with AES-256-GCM: a fresh data key per secret, wrapped by a master key held only in the server environment. It is decrypted inside background sync jobs and never returned to a browser, a log or a job result. The interface shows the last four characters only.
Isolated per workspace
Every record carries your workspace id and every query filters on it. Stripe objects are keyed on (workspace, Stripe id), so one platform's data cannot collide with or be read by another's.
Only what the product needs
Payments, disputes, refunds, payouts, fraud reports and account requirements, with the card details Stripe exposes to you: brand, last four, fingerprint and the outcome of its checks. We never see full card numbers; Stripe doesn't expose them to anyone.
Revocable in a second, from either side
Disconnect in Settings and the stored key is deleted. Expire the key in Stripe and our access ends instantly, whatever state we are in. Ask and we delete your synced history.
Authentication you control
Sign-in, workspaces and roles are handled by Clerk, with multi-factor authentication available to every user. Only workspace admins can connect, rotate or disconnect a Stripe key or change where alerts go.
The seven rows we ask for.
These are the exact rows in Stripe's restricted-key editor, each set to Read. Every other row stays on None. This is the same list the product checks against when you connect, so what we publish and what we test can't drift apart.
- Accountsyour accountThe list of your connected accounts and whether each can take payments.
- Charges and Refundsyour account and connected accountsPayment volume, refunds and the card details behind risk scores.
- Payment Disputesyour account and connected accountsChargebacks, dispute ratios and evidence deadlines.
- Balanceyour account and connected accountsStripe's fee on each payment, and whether an account's balance covers its open disputes.
- Payoutsconnected accountsPayout history and failed payouts for each connected account.
- Early Fraud Warningsyour account and connected accountsCard-network fraud reports, so you can refund before the chargeback lands.
- Application Feesyour accountWhat your platform earns on each payment.
Where your data lives.
The database is Neon serverless Postgres in AWS us-east-2 (Ohio); the application runs on Vercel and background jobs on Inngest. Transactional email goes through Resend, only when you configure it. Each provider publishes its own security practices and certifications; we don't operate servers of our own.
Found something? Write to us through the contact page and mark it security. Those are read first.
Read-only is the whole point.
Connect a restricted key, look at your own numbers, and expire the key the moment you decide it isn't for you.
Read-only restricted key · Verified before it is stored · Revoke it in Stripe any time