Security

We run our own controls against ourselves.

Five published controls: enforced multi-factor auth, strict tenant isolation, write-once evidence with an append-only audit trail, encryption at rest, and least privilege throughout.

Enforced multi-factor authentication

Every user enrolls MFA before they can access the product.

Strict tenant isolation

Every organization is a separate tenant. Your data is isolated from other tenants.

Write-once evidence + append-only audit trail

Evidence you upload is write-once. Every action (who did what, when) is logged in an append-only audit trail.

Encryption at rest

Database and object storage are encrypted at rest.

Least privilege throughout

Access control follows least privilege. Users only have the access their role requires.

What we do not claim

GapLedger is not itself ISO 27001 certified. We run the five published controls above, and we run our own ISMS against ourselves using the product. We do not publish a SOC 2 report on GapLedger.

Start your 14-day trial

See the controls in action. 14-day trial, no card required.

Frequently asked questions

Is GapLedger ISO 27001 certified?

No. GapLedger is compliance management software, and we run the five published controls above. We do not claim that GapLedger itself is ISO 27001 certified.

Does GapLedger have a SOC 2 report?

No. We do not publish a SOC 2 report on GapLedger. We run the five published controls, and we run our own ISMS against ourselves using the product.

Can I delete evidence after I upload it?

Evidence is write-once. The audit trail logs who did what and when. This is how we prove integrity when your auditor asks.