LedgerClearLedgerClear

Security & trust

An unknown vendor asking for access to your books should have to show its work.

We don’t have logos or testimonials to borrow trust from, so the trust is structural: what we request, what we refuse to request, what we can never do, and what we tell you we can’t see.

Read-only scopes

The scan connects to Shopify and QuickBooks Online with read scopes. The scan itself cannot write anything, anywhere. Write access exists only in the paid cleanup flow, entry by entry, on your click.

Field minimization

We never request customer names, emails, or addresses - from either system. The scan reads amounts, taxes, quantities, and order/payout/refund IDs only. Data we don’t request is data we can’t lose. The demo fixtures follow the same rule: there is no personal data anywhere in this build.

Propose-only writes

  • Nothing posts without your per-entry approval.
  • Every posted entry ships with an auto-generated reversing entry, prepared before you approve.
  • Corrections dated inside a closed or filed tax period (VAT and US filed sales tax alike) are propose-only, always - they can never be posted from LedgerClear.
  • Nothing here is tax advice; filed-period items route to your bookkeeper.

Immutable audit log

Every read, proposal, approval, and post is recorded in an insert-only audit log - updates and deletes are rejected at the database level. In the demo you can watch it accumulate on the cleanup page as you approve entries.

What we can’t see

An auditor that hides its scope isn’t an auditor. LedgerClear cannot see, and therefore cannot check:

  • Bank feeds. If a discrepancy’s root cause lives in your bank feed, we say so and point you to a bookkeeper rather than guessing.
  • POS and non-Shopify channels. Amazon, wholesale, in-person sales - out of scope.
  • Manual journal entries’ intent. We can see that books were adjusted by hand, not why. That’s what per-finding “mark intentional” is for.
  • Summary-posting pipes at launch. v1 audits per-order syncs. Summary-posting tools (A2X, Bookkeep) need a configured tier that comes later - we don’t claim them today.

Disconnect and delete

One click revokes both OAuth tokens and deletes your cached data. When monitoring ships, a connection that dies on its own will show “paused” and billing will pause with it - silence should never be sold as healthy books. Monitoring is not running today, so there is nothing yet to pause and nothing being billed for it.

See it before you connect anything

The strongest trust signal we can offer is the product itself, on sample data, with zero credentials.

Run the free scan (demo)