Ledger by Empyre

Ledger privacy policy

Ledger holds the financial records you create or connect: transactions, journal entries, invoices, bills, uploaded documents, counterparties and the legal entities you configure, together with account information, audit logs and usage counters.

Ledger does not store full card numbers, card security codes or full bank account numbers, and API keys are stored only as a cryptographic hash. Empyre staff cannot log in as you; support reads happen in a scoped, expiring, read-only session recorded against the operator in a separate audit trail.

How Ledger works

Ledger is the financial operating system for a company run by AI agents. It keeps real double-entry books where debits equal credits by database constraint, tracks cash and runway continuously, accepts payments directly into the company's own Stripe account, enforces spending limits that AI agents cannot exceed, and estimates the tax that should be reserved.

Its CFO answers questions about the company's finances using figures computed by trusted code rather than produced by a language model. The model decides which questions to ask of the books and how to explain the answer; every amount, margin, runway figure and ownership percentage is calculated in integer minor units by the accounting engine.

Developers integrate through @empyre/ledger-sdk on npm (zero runtime dependencies, Node 18+, Deno, Bun, browsers and edge runtimes) or the REST API directly. The SDK covers revenue ingestion with caller-supplied idempotency so a retried sale is never counted twice, the books, runway and the required-change solver, the CFO, agent spend requests, and constant-time webhook verification whose signature covers a timestamp so a captured delivery cannot be replayed.

Around the books sit the records a finance team actually works from. Budgets compare each line to posted journal entries in that budget's own period, so the variance is the same figure the reports show rather than a number typed in beside it. Documents — receipts, invoices, statements and contracts — are stored privately, de-duplicated by the hash of their contents rather than by filename, and attached by hand to the transaction or bill they evidence; Ledger does not read amounts off a document and does not claim to. Agent spending policies are created and switched off in the product, with each requester's real thirty-day spend shown beside the policy governing it. And every write leaves an audit row the account holder can read and filter, separate from the operator trail Empyre staff actions are recorded in.

Public pages

JavaScript is required to sign in and use the Ledger dashboard. The product information above and the linked public pages remain readable without it.