Technical Specifications. A Look Under the Hood.
Explore the deployment topology, local storage engine, and zero-trust networking that make AES-LedgerPro genuinely self-hosted, private, and resilient. Runs on https://localhost:8443 and is reachable across the local network.
From Fresh Download to Production Accounting
Get up and running in minutes on any standard Windows workstation or local server. Download, run it, it works — no request step, no waiting period.
Download Windows Executable Suite
Obtain the three standalone Windows binaries (Ledger_Server.exe, Ledger_Remote_Service.exe, Ledger_Device_Manager.exe) packaged via PyInstaller with zero required runtimes.
Set Your Master Password & Generate Salt
Your master password derives the AES-256-GCM vault key via PBKDF2-HMAC-SHA256 with 200,000 iterations. Salt and nonces are generated per-write with zero plaintext staging.
Embedded SQLite Vault Initialized
The system creates the encrypted ledger.vault database file directly on local NVMe/SSD storage. Double-entry chart of accounts is configured for your tax jurisdiction.
LAN Auto-Discovery for POS & Terminals
Point-of-sale tablets, barcode scanners, thermal receipt printers, and timeclock terminals on your local subnet automatically connect to https://localhost:8443 without configuration.
Pair Citadel Relay via Firestore Key
For secure off-site access, provide your own Firebase/Firestore credentials ('Bring Your Own Key'). The host establishes an outbound-only tunnel with zero open router ports.
Audit Hash Integrity at Any Time
Every posting commits to an append-only SHA-256 cryptographic hash chain alongside the double-entry trial balance check, verifiable at any moment inside the app.
Where Your Data Lives & How It Moves
Every layer of AES-LedgerPro is structured to ensure that no financial record, employee wage slip, or inventory level ever touches a vendor server.
Local Host Machine (Windows 10/11 / Server)
Application Server
Compiled standalone executable (Ledger_Server.exe) running on https://localhost:8443.
Encrypted Database
All tables, accounts, payroll slips, and audit hash entries encrypted at rest.
Document Engine
Direct HTML-to-PDF rendering for high-resolution invoices, pay slips, and financial statements.
Internal Business Subnet (Zero Internet Needed)
POS Tills & Registers
Instant till reconciliation, barcode camera capture, and Bluetooth/serial thermal printing.
Timeclock Terminals
Timesheets feed directly into the Basilica payroll engine without external SaaS sync.
Back-Office Workstations
Accessible via modern desktop browser at https://[local-ip]:8443 with TLS certificates.
Optional Outbound-Only Secure Tunnel
Outbound Broker
Reaches outward to customer-isolated Firestore endpoints. Zero inbound router ports opened.
Device Manager
Every remote device must be explicitly authorized in Ledger_Device_Manager.exe.
Ed25519 Signing
License validation and remote session handshake signed via Ed25519 keypairs.
Three Executables. One Click Each.
AES-LedgerPro requires all three signed Windows executables. Download each directly — packaged via PyInstaller with zero third-party runtimes.

Device Manager
Ledger_Device_Manager.exe
Hardware pairing console & local node management interface.

Remote Access
Ledger_Remote_Service.exe
Encrypted local client connection gateway for off-site nodes.

Ledger Server
Ledger_Server.exe
Main core application, double-entry accounting database & POS engine.
Verified Setup Manuals & PDF Documentation
Official documentation covering remote access relay configuration, email servers, and Akahu bank feeds.
Billing & Subscription Guide
Complete overview of trial periods, licensing states, and direct bank transfer mechanics.
Remote Access Key Setup Guide
Step-by-step instructions to provision your private Firestore key for secure zero-trust remote access.
Custom Email Setup Guide
Configure your custom Google Apps Script email sender for branded invoice and payslip delivery.
Akahu Bank Feed Setup Guide
Connect your New Zealand bank accounts directly for automated, encrypted transaction imports.
