Skip to main content

SiteLedger

Security and access

SiteLedger holds commercial information about real sites, so the controls below are the ones that decide who can open what. This page describes how the product behaves, not how we would like it to sound.

Last updated August 2026.

Nothing operational is public

Every operational page requires a signed-in session. A visitor who is not signed in is sent to the sign-in page rather than shown a page with the contents removed, and document downloads are refused rather than served empty.

The pages you are reading now — the home page and these public pages — are the entire public surface. They read no session and query no customer information.

Information is scoped to the organisation it belongs to

Records are tied to the company that owns them, and queries are filtered by the companies your account can reach. A record belonging to another organisation is not hidden in the interface — it is not returned.

Where a page would otherwise reveal that a record exists simply by behaving differently for a valid identifier, it deliberately behaves the same way as it does for one that does not exist.

Documents

Uploaded files are stored in managed cloud object storage and retrieved through the application, which checks entitlement on each request. A document reference on its own is not a way in.

Sessions and credentials

Sign-in uses an email address and a password issued through your organisation. Passwords are stored as one-way hashes; nobody administering SiteLedger can read yours. Sessions are held in a signed cookie and can be ended by signing out.

Where SiteLedger runs

The application runs on managed cloud infrastructure, with the database and file storage provided by managed services rather than a machine under somebody’s desk. Traffic is served over HTTPS.

What we do not claim

SiteLedger does not hold ISO 27001, SOC 2 or any equivalent certification, and this page will not imply one. If a certification is ever obtained, it will be named here with its scope and date.

Questions about access, accounts or a specific control belong with your organisation’s SiteLedger administrator, who can also arrange for them to reach us.

How information is handled is described in the privacy notice.

Back to the SiteLedger home page