New Zealand Made · Verified FIPS-Aligned Local Stack
Citadel Security Architecture

Cryptographic Sovereignty. No Backdoors. No Cloud Risks.

AES-LedgerPro operates under a strict zero-knowledge and zero-trust model. Built on industry-standard, well-audited cryptographic primitives — fully disclosed and independently verifiable.

REGULATORY COMPLIANCE & FIPS 140 ALIGNMENT

Federal Cryptographic Standard Alignment

To address strict regulatory and commercial compliance mandates, AES-LedgerPro relies exclusively on FIPS-compliant algorithms. When deployed on a FIPS 140-validated operating system (such as Windows with FIPS mode enabled) or utilizing FIPS 140-certified cryptographic modules (OpenSSL FIPS provider bindings), the underlying encryption engine operates in full alignment with federal standards.

FIPS Primitives

AES-256 (GCM), HMAC-SHA256, and SHA-256 only.

Key Isolation

Client password derives key locally. Zero vendor escrow.

Fail-Safe Licensing

Temporary network drops never lock you out of your ledger.

Cryptographic Disclosure

Cryptographic Primitives & Implementation

We do not invent proprietary ciphers. Every layer of Citadel is anchored in public, peer-reviewed cryptography.

AES-256-GCM

Vault Cipher

Authenticated Galois/Counter Mode. The entire embedded SQLite database (ledger.vault) is encrypted at rest. Provides both confidentiality and cryptographic authenticity checking on every block read.

Zero Cloud Escrow
PBKDF2-HMAC-SHA256

Key Derivation Function (KDF)

Stretched through 200,000 iterations derived directly from the operator's master password. Ensures immense computational resistance against brute-force attacks.

Zero Cloud Escrow
Cryptographically Secure PRNG

Salt & Nonce Management

A unique, cryptographically random salt and 96-bit nonce are generated on every single disk write transaction, entirely eliminating nonce-reuse vulnerabilities.

Zero Cloud Escrow
SHA-256 Cryptographic Hash Chain

Ledger Audit Chain

Every journal posting and void event commits to an append-only cryptographic chain where each link cryptographically seals the hash of the preceding entry.

Zero Cloud Escrow
Ed25519 High-Speed Signatures

Remote Licensing Authentication

License state transitions (activation, renewal, offline grace periods) are cryptographically validated using 128-bit security level Ed25519 signature verification.

Zero Cloud Escrow
AES-256-GCM Direct File I/O

Encrypted Document Store

Receipt photos, employee contracts, and job site captures are streamed directly into the encrypted vault without unencrypted temporary disk staging.

Zero Cloud Escrow
Mathematical Ledger Defense

Tamper-Evident SHA-256 Audit Hash Chain

In conventional cloud accounting software, a database administrator or rogue vendor script can quietly alter historical ledger records without trace. In AES-LedgerPro, every journal transaction and void entry writes to a cryptographically linked, append-only hash chain.

1

Continuous Linkage: Each entry encodes the SHA-256 checksum of the preceding entry, forming an unbroken cryptographic chain.

2

In-App Self Verification: The business operator or independent auditor can recompute the entire ledger hash sequence with a single click in the console at any time.

3

Dual Verification: The hash chain operates alongside an independent real-time trial balance check (Σ Debits == Σ Credits), ensuring mathematical integrity at both the cryptographic and accounting layers.

Cryptographic Chain InspectorVerification: 100% PASS
ENTRY #10842 · General JournalVALID

PrevHash: 0000000000000000000...49a1f2e8

CurrHash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

↓ SHA-256 Link Sealing ↓
ENTRY #10843 · POS Sales BatchVALID

PrevHash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

CurrHash: 7f83b1657ff1fc53b92dc18148a1d65dfc2d4b1fa3d677284addd200126d9069

↓ SHA-256 Link Sealing ↓
ENTRY #10844 · Pay Run CommitmentVERIFIED

PrevHash: 7f83b1657ff1fc53b92dc18148a1d65dfc2d4b1fa3d677284addd200126d9069

CurrHash: 4b227777d4dd1fc61c6f884f48641d02b4d121d3fd328cb08b5531fcacdabf8a

Citadel Zero-Trust Gateway

Zero Inbound Ports. Bring Your Own Firestore Key.

Unlike legacy self-hosted accounting tools that demand risky port forwarding (exposing port 80 or 443 directly to internet port scanners), AES-LedgerPro’s Citadel Relay operates on an outbound-only connection model.

Outbound-Only Tunnel

The local server reaches outwards to broker remote access. Your office router has zero inbound port rules opened to the public internet.

Customer-Owned Firestore

Relay coordination runs via your own private Google Cloud / Firebase project ("Bring Your Own Key"). Sovereign Services does not proxy your traffic.

Cryptographic Device Approval

Every external smartphone or tablet must be explicitly paired and pre-approved inside the on-premise Device Manager before any session is granted.

Audit Your Own Books with Sovereign Confidence

Experience the peace of mind that comes from owning your encryption keys, database files, and accounting software outright.