Security at Personnel Ledger
Last updated October 5, 2026
This page is a plain-language overview of how we protect your organization's staff records. We describe only what we actually do: no inflated claims and no certifications we don't hold. Personnel Ledger is operated by MortonApps LLC.
Staff records are sensitive too
A personnel file holds license numbers, background check dates and health screening results. Personnel Ledger is built to keep that to what a file needs: most requirements are a status and a date, and uploading the document behind one is your choice, not a requirement.
Encryption in transit and at rest
- In transit: all traffic between your browser and the service is encrypted over HTTPS (TLS).
- At rest: records are stored in Cloudflare's managed database (D1) and uploaded documents in Cloudflare's object storage (R2), both of which encrypt data at rest.
Sign-in and sessions
- Passwords are hashed with PBKDF2-HMAC-SHA256 using a per-user random salt. We cannot see or recover your password.
- Each person sets their own password from a single-use invite or reset link; administrators never type or see another user's password.
- Sessions are server-side: the browser holds only an HttpOnly cookie that scripts cannot read, and the session token is stored hashed, so a database leak would not expose usable tokens.
Access controls and isolation
- Role-based access within each organization: roles decide who can change records and who can only view them.
- Kept separate: each customer's data lives in its own workspace, and every database query is limited to that customer.
- Reminders go by email only. The people you track receive reminders at the email address on their record; they do not need an account, and no message goes out by any other channel.
Hosting
- The application runs on Cloudflare's global network (Cloudflare Pages and Functions), with data in Cloudflare D1 and documents in Cloudflare R2.
- Your organization can export its records to CSV at any time. We recommend exporting periodically as your own independent copy.
- There are no third-party tracking or advertising scripts in the app.
How we handle your data
- We collect only what the service needs to run. Apart from a sale or reorganization of our business, we never sell data for money, never run ads in the service, and never use customer data to train AI models ourselves. Our AI provider, Anthropic, may use what we send it for its own purposes, as our Privacy Notice explains.
- Your organization owns its data and can export or request deletion of it at any time.
- If we ever discover a breach involving your data, we will notify affected organizations without undue delay.
What we don't claim
Personnel Ledger is a small, focused product. We are not currently SOC 2, ISO 27001 or HIPAA certified, and we don't claim to be. Our security model is built on keeping the product simple, the attack surface small, and patient information out of the system entirely. No internet service can promise perfect security, but we design conservatively and tell you the truth about what we do.
Reporting a concern
If you have a security question, or believe you've found a vulnerability, please email [email protected]. We read it during business hours and respond to security reports as quickly as we can.
See also our Privacy Notice.