New Zealand Made · Verified FIPS-Aligned Local Stack
System Architecture & Deployment

Technical Specifications. A Look Under the Hood.

Explore the deployment topology, local storage engine, and zero-trust networking that make AES-LedgerPro genuinely self-hosted, private, and resilient. Runs on https://localhost:8443 and is reachable across the local network.

Step-by-Step Deployment

From Fresh Download to Production Accounting

Get up and running in minutes on any standard Windows workstation or local server. Download, run it, it works — no request step, no waiting period.

01No Docker or Node required

Download Windows Executable Suite

Obtain the three standalone Windows binaries (Ledger_Server.exe, Ledger_Remote_Service.exe, Ledger_Device_Manager.exe) packaged via PyInstaller with zero required runtimes.

Sovereign Local Execution
02PBKDF2 · 200,000 Rounds

Set Your Master Password & Generate Salt

Your master password derives the AES-256-GCM vault key via PBKDF2-HMAC-SHA256 with 200,000 iterations. Salt and nonces are generated per-write with zero plaintext staging.

Sovereign Local Execution
03Single-Tenant Local Vault

Embedded SQLite Vault Initialized

The system creates the encrypted ledger.vault database file directly on local NVMe/SSD storage. Double-entry chart of accounts is configured for your tax jurisdiction.

Sovereign Local Execution
04100% Offline Compatible

LAN Auto-Discovery for POS & Terminals

Point-of-sale tablets, barcode scanners, thermal receipt printers, and timeclock terminals on your local subnet automatically connect to https://localhost:8443 without configuration.

Sovereign Local Execution
05Outbound-Only Broker

Pair Citadel Relay via Firestore Key

For secure off-site access, provide your own Firebase/Firestore credentials ('Bring Your Own Key'). The host establishes an outbound-only tunnel with zero open router ports.

Sovereign Local Execution
06Self-Verifiable Chain

Audit Hash Integrity at Any Time

Every posting commits to an append-only SHA-256 cryptographic hash chain alongside the double-entry trial balance check, verifiable at any moment inside the app.

Sovereign Local Execution
Full-Stack Architectural Topology

Where Your Data Lives & How It Moves

Every layer of AES-LedgerPro is structured to ensure that no financial record, employee wage slip, or inventory level ever touches a vendor server.

Tier 1: Client Hardware Core

Local Host Machine (Windows 10/11 / Server)

All calculations, double-entry ledgers, and files remain within client-owned physical hardware boundaries.
Python 3.11 + Flask WSGI

Application Server

Compiled standalone executable (Ledger_Server.exe) running on https://localhost:8443.

100% Client-Owned Hardware
SQLite (ledger.vault) + AES-256-GCM

Encrypted Database

All tables, accounts, payroll slips, and audit hash entries encrypted at rest.

100% Client-Owned Hardware
Headless Chromium Pipeline

Document Engine

Direct HTML-to-PDF rendering for high-resolution invoices, pay slips, and financial statements.

100% Client-Owned Hardware
Tier 2: Local Network Environment

Internal Business Subnet (Zero Internet Needed)

Point-of-sale counters, warehouse picking tablets, and kitchen displays communicate across local Wi-Fi / Ethernet.
Quick-Sale & Table Service Floors

POS Tills & Registers

Instant till reconciliation, barcode camera capture, and Bluetooth/serial thermal printing.

100% Client-Owned Hardware
Employee PIN Time Recording

Timeclock Terminals

Timesheets feed directly into the Basilica payroll engine without external SaaS sync.

100% Client-Owned Hardware
Carbon Series Web Console

Back-Office Workstations

Accessible via modern desktop browser at https://[local-ip]:8443 with TLS certificates.

100% Client-Owned Hardware
Tier 3: Citadel Zero-Trust Remote Access

Optional Outbound-Only Secure Tunnel

Access your ledger securely from home or on the road without exposing office firewall ports to the public internet.
Citadel Relay Daemon

Outbound Broker

Reaches outward to customer-isolated Firestore endpoints. Zero inbound router ports opened.

100% Client-Owned Hardware
Cryptographic Pairing Gate

Device Manager

Every remote device must be explicitly authorized in Ledger_Device_Manager.exe.

100% Client-Owned Hardware
Cryptographic Licensing

Ed25519 Signing

License validation and remote session handshake signed via Ed25519 keypairs.

100% Client-Owned Hardware
Standalone Windows Deployment Binaries

Three Executables. One Click Each.

AES-LedgerPro requires all three signed Windows executables. Download each directly — packaged via PyInstaller with zero third-party runtimes.

Device Manager

Device Manager

Ledger_Device_Manager.exe

Hardware pairing console & local node management interface.

Remote Access

Remote Access

Ledger_Remote_Service.exe

Encrypted local client connection gateway for off-site nodes.

Ledger Server

Ledger Server

Ledger_Server.exe

Main core application, double-entry accounting database & POS engine.