LedgerTB is desktop double-entry bookkeeping for client work — trial balance to close, in one encrypted file on your machine. No server. No subscription. No one else holding your clients' data.
Open source under MIT · macOS (notarized) and Windows · built by a practicing CPA
Clients in, transactions in, judgments made, statements out — with the trial balance worksheet at the center, the way working papers actually flow.
Per-client books with entity-type templates, or bring your own chart — QuickBooks type names understood, numberless charts get numbers assigned by type range, and unmappable rows are reported, never silently dropped.
CSV imports with saved per-bank formats, duplicate detection, and row-continuity checks — because a balanced trial balance is not proof an import was complete.
Claude suggests the account for each imported transaction and learns your patterns. Suggestions only: you review, you post, and the audit trail records both.
Unadjusted balances, adjusting entries, adjusted balances — the working paper CPAs actually use, not a report bolted on afterward.
Trial balance, income statement, balance sheet, general ledger, bank reconciliation — and an exportable close package (PDF + Excel) carrying your firm's branding.
A deterministic integrity sweep — unbalanced entries, unposted imports, broken links, date problems, quiet accounts — plus an AI category-consistency review under your own per-client policy notes.
Every change is logged with the OS account that made it. Assistant actions are stamped "(AI)" — automated work is never presented as yours.
Book files can live on a shared drive. The app installs locally, each book has its own passphrase, and an in-use lock keeps two writers out of one book.
Validation lives in the engine, not the screen. If it doesn't balance, it doesn't post — no matter who, or what, is typing.
Connect Claude (or any MCP client) to the book you have open. You choose how much it can do — and the database engine enforces the choice, not a promise in a prompt.
Query everything: trial balance, statements, ledgers, entry search, the integrity sweep. Nothing is written but the audit trail.
Set up clients and charts, stage imports from any statement format, file draft entries — all into inboxes that wait for your review.
Post balanced entries directly, with an explicit warning before you turn it on. Append-only: nothing can ever be edited or deleted from here.
Client books are professional records. LedgerTB treats them that way by default.
The book file is encrypted behind a launch passphrase only you hold. Backups are encrypted the same way, and verified before they count. Two things you can turn on — "remember on this computer" and assistant access — store the unlock key in your operating system's credential vault, so anyone who can sign in to that computer account opens the book without the passphrase. Both are off unless you choose them.
The app binds to your machine only. The one outbound call is Anthropic categorization, and only if you enable it. No telemetry.
The whole application is readable, auditable, and yours to keep. Signed and notarized builds for macOS; CI-built installers for Windows.
LedgerTB is software, not accounting advice. It enforces the mechanics — balanced entries, an append-only ledger, an audit trail — but every judgment in the books is yours, whether you made it directly or accepted a suggestion. That's not a disclaimer; it's the design. The tool keeps the record honest, and the professional stays the professional.
Both downloads are built from the tagged source. Windows is built by GitHub Actions; macOS is signed and notarized on Apple Silicon. Your books live under your user profile, never inside the app — upgrading keeps your data, uninstalling doesn't delete it.
Apple Silicon. Signed and notarized — it opens with no warnings. Unzip and drag to Applications.
Download for MacInstalls for you alone — no administrator password, so it works on a locked-down firm laptop.
Download for WindowsWindows shows a SmartScreen warning because this build's publisher identity isn't verified yet — click More info → Run anyway. That warning is about identity, not safety: the source is public and every build comes from CI. A signed build is planned.