Security policy
Ledgerly · 24/09/2026
BackThe security of Ledgerly and our users' data is a priority. If you are a security researcher and believe you have found a vulnerability, this page explains how to report it responsibly. We welcome any good-faith report.
Scope
The following are in scope for this policy,
- the web application on ledgerly.be and its subdomains
- the account area, authentication, session and access management
- the invoicing, VAT and accounting business logic
Out of scope
The following activities and reports are not accepted,
- denial-of-service attacks (DoS, DDoS) and load testing
- phishing, social engineering targeting our users or staff, spam
- physical access, testing of the third-party services we rely on (payment, hosting, banking)
- reports based solely on automated scanners without proof of real impact
Rules to follow
- Test only with an account you created yourself, never access another user's data.
- Do not extract, modify or delete any data, stop as soon as a flaw is demonstrated.
- Do not degrade the service or disrupt its operation for other users.
- Do not publicly disclose the vulnerability before it is fixed and we have given our consent.
How to report a vulnerability
Send us a detailed report by email. We will get back to you as soon as possible.
Security contact, security@ledgerly.be
- a clear description of the vulnerability and its potential impact
- precise steps to reproduce it (URL, requests, screenshots)
- where relevant, a suggested fix
Our commitment
If you follow this policy and act in good faith,
- we acknowledge your report and keep you informed of its handling
- we fix confirmed flaws within a reasonable time depending on severity
- we will not take legal action against you for testing carried out in line with these rules
Reward
Ledgerly does not offer a paid bug bounty program at this time. We do, however, warmly thank researchers for their contribution and may, with their consent, credit them publicly once the flaw is fixed.