Skip to content
ledgerbase
DocsLearnCatalogJoin Our CommunityFAQStatusRequest API key
MVP-limited ticker coverage. This is an early MVP — only eight tickers are ingested: AAPL, AMZN, JPM, MSFT, NVDA, TSLA, WMT, and XOM. Any other ticker returns no data.
Security
01Reporting a vulnerability02Scope03What to expect04API keys and data handling
Security

Security Policy

LedgerBase handles API keys and SEC-derived financial data. If you find a security issue, we want to know before anyone else does.

Last updated: July 21, 2026
01

Reporting a vulnerability

Email [email protected] with a description of the issue, steps to reproduce, and the potential impact. Please do not open a public GitHub issue or post details publicly before we’ve had a chance to respond.

We aim to acknowledge reports within 3 business days. LedgerBase is an early-stage product — this is a best-effort disclosure process, not a formal bug-bounty program.

Machine-readable version: /.well-known/security.txt (RFC 9116).

02

Scope

In scope:

  • The public landing site and its API routes.
  • The LedgerBase backend API (/v1/*) and API-key issuance flow.
  • The ledgerbase-iris-cli client.

Out of scope:

  • Denial-of-service testing, automated vulnerability scanners run at volume, and social engineering against LedgerBase staff.
  • Findings that require a compromised or physically-accessed device.
03

What to expect

LedgerBase does not currently offer paid bug-bounty rewards. Valid reports are fixed and, with the reporter’s permission, credited in the changelog.

04

API keys and data handling

API keys are shown once at issuance and are not recoverable — see the docs Authentication topic. Report a suspected leaked or compromised key to [email protected] so it can be revoked.

See the Privacy Policy for what information LedgerBase processes.

ledgerbase
Product
DocsStatusRequest API key
Feedback
Request a featureReport a bugFAQChangelog
Company
AboutContactSecurityTermsPrivacy

© 2026 LedgerBase, Inc. SEC data sourced from public EDGAR filings.