Security
We run our own controls against ourselves.
Five published controls: enforced multi-factor auth, strict tenant isolation, write-once evidence with an append-only audit trail, encryption at rest, and least privilege throughout.
Enforced multi-factor authentication
Every user enrolls MFA before they can access the product.
Strict tenant isolation
Every organization is a separate tenant. Your data is isolated from other tenants.
Write-once evidence + append-only audit trail
Evidence you upload is write-once. Every action (who did what, when) is logged in an append-only audit trail.
Encryption at rest
Database and object storage are encrypted at rest.
Least privilege throughout
Access control follows least privilege. Users only have the access their role requires.
What we do not claim
GapLedger is not itself ISO 27001 certified. We run the five published controls above, and we run our own ISMS against ourselves using the product. We do not publish a SOC 2 report on GapLedger.
Start your 14-day trial
See the controls in action. 14-day trial, no card required.
Frequently asked questions
Is GapLedger ISO 27001 certified?
No. GapLedger is compliance management software, and we run the five published controls above. We do not claim that GapLedger itself is ISO 27001 certified.
Does GapLedger have a SOC 2 report?
No. We do not publish a SOC 2 report on GapLedger. We run the five published controls, and we run our own ISMS against ourselves using the product.
Can I delete evidence after I upload it?
Evidence is write-once. The audit trail logs who did what and when. This is how we prove integrity when your auditor asks.