Enterprise-Grade Trust & Architecture

Security & Data Governance

How ColdLedger protects Australian & New Zealand financial ledgers with ephemeral processing, read-only permissions, and air-gapped offline storage.

Ephemeral Pipeline (Zero Secondary Database)

Most cloud apps ingest your ledger into their own permanent cloud database, creating a new attack surface. ColdLedger processes data on isolated ephemeral workers, packages your offline ZIP, and automatically purges scratch volumes within 48 hours.

No secondary financial data warehouse

Strict Read-Only API Authorization

We strictly connect via official MYOB OAuth 2.0 with read-only scopes. ColdLedger cannot create, alter, balance, delete, or tamper with transactions in your live company file. Your live files remain untouched.

Zero write or delete permissions requested

Air-Gapped Offline Viewer Portability

Your archive includes Open_Vault.html. It has zero external scripts, zero CDN dependencies, and zero phone-home network calls. You can disconnect your internet entirely and inspect your books in any browser.

Independent of ColdLedger or MYOB uptime

Australian Data Sovereignty

All cloud extraction containers and encrypted staging buckets operate within Tier-3 Australian data centres located in Sydney, Australia, fully compliant with Australian Privacy Principles and ATO data sovereignty expectations.

Sydney (ap-southeast-2) data residency

Cryptographic Integrity Verification (SHA-256)

When an archive is sealed, ColdLedger generates a cryptographic SHA-256 hash manifest (manifest.json) detailing the checksum of every extracted CSV ledger, journal row, and In-Tray binary file. In the event of an ATO or IRD compliance audit, this cryptographic hash serves as indisputable evidence that records have not been altered post-extraction.

Encryption Standards

  • In Transit: All communication between your browser, ColdLedger workers, and MYOB API endpoints occurs exclusively over TLS 1.3 with strict HSTS (HTTP Strict Transport Security).
  • At Rest: Temporary staged zip files are encrypted using AES-256 before being queued for client download.
  • Tokens: Short-lived OAuth tokens are stored in memory or AES-256 encrypted fields and purged when the session terminates.

Isolated Multi-Tenant Architecture

Accounting practices manage files on behalf of distinct corporate entities. ColdLedger ensures that each extraction job runs in a dedicated sandbox container. Memory space, temporary scratch directories, and authentication tokens are strictly segregated to prevent any possibility of cross-client data contamination.

Need a Firm Security Questionnaire or DPA?

We provide direct technical responses to accounting practice security and IT teams.

Contact Security Desk