Skip to content
Get access

Comparisons · PG-14 · Formance

Ledgerbook AI vs Formance

A money-movement ledger and an accounting data layer — adjacent, not interchangeable. Every claim below was verified against Formance's public materials on 2026-09-19, with sources linked.

Last verified 2026-09-19 · re-verified quarterly · corrections → contact

Formance is a money-movement ledger: an MIT-licensed core with a hash-linked, bi-temporal log, payments connectivity, flows and reconciliation — and roughly 60% of its paying customers self-host (their deployment page, fetched 2026-09-19). Ledgerbook sits a layer higher: the accounting book of record above money movement, with multi-entity consolidation semantics, a Provisional → Final lifecycle with typed corrections, per-scenario double-entry and OCEL 2.1 audit exports. These are adjacent products, not substitutes: Formance's exporters and API are a legitimate ingestion source for Ledgerbook, and a company can run both. This page states where Formance is ahead — certifications, payments connectors, delivered enterprise self-host — and where the layers differ, from dated public sources.

Verified 2026-09-19 · sources: formance.com platform, deployment, pricing and security pages · AWS Marketplace listing · GitHub repo (dossiers 07/12, same date)

Side by side

Facts captured 2026-09-19 from sources linked under this table; vendor marketing is labelled as such. Ledgerbook cells carry phase tags: PH-1 or the Roadmap pill.
DimensionFormanceLedgerbook AI
Deployment MIT OSS core self-deployable; enterprise self-host (K8s operator, Helm) or single-tenant private cloud; roughly 60% of paying customers self-host. their deployment page, 2026-09-19 Self-host and air-gap first-class: single node, basic HA, offline bundle with zero egress. NFR-6 · PH-1 Embedded class and multi-region residency are Roadmap
Immutability & corrections Append-only, hash-linked log; bi-temporal since ledger v2 (Jun 2024); corrections as reversal entries rather than mutation. their docs and release notes, 2026-09-19 Chain hash on every Final entry, enabled by default and not disableable by writers; corrections only as typed reversing, adjusting or restating entries. FR-118/119/123–125/214 · PH-1 Zero-knowledge assertions are a stub contract plus one test vector; the backend is Roadmap
Agent write path (MCP) MCP is read-only and enterprise-cloud-gated (launched 2026-08-05); agent writes go through API clients with RBAC. their MCP changelog, 2026-08-05 MCP read/propose with the same semantics and error taxonomy as HTTP — including air-gapped with your local model; agents cannot approve, finalize or correct, enforced at the credential. Tiers T0/T1 ship; T2/T3 are Roadmap. FR-220/343 · PH-1
Accounting depth Money-movement and asset ledger: namespaced accounts, multi-asset, ledger schemas; no multi-dimensional chart of accounts, no statutory posting validation, no ERP or GL-ingestion layer. their platform docs, 2026-09-19 Multi-dimensional accounts and dimension registry; per-scenario double-entry; multi-entity intercompany as explicit paired entries; posted FX conversion with the rate locked at posting. Compliance packs and statutory validation are Roadmap. FR-102/103/128–134/335 · PH-1
Provenance / audit export Hash-chained audit logs and SIEM export; replayable data exporters to warehouses; no OCEL 2.1 object-centric export. their enterprise and security pages, 2026-09-19 OCEL 2.1 JSON export plus an independently runnable verifier; a provenance event on every mutation with who/when/where. Bundled export formats and packaged evidence sets are Roadmap. FR-905/121 · PH-1
Commercial shape MIT core free; one annual enterprise subscription, custom quote, effective base of roughly $120K/year per their AWS Marketplace listing; no per-transaction metering on the base. their pricing page + AWS listing, 2026-09-19 Open-core, source-available stance (licence text to publish before commercial launch); quote-led enterprise, no per-transaction metering on the base. OI-12/19

Sources: formance.com/platform/deployment · formance.com/pricing · formance.com/blog/changelog/formance-mcp-server · formance.com/platform/security · AWS Marketplace listing · github.com/formancehq/ledger — all fetched 2026-09-19. For our column: product specification, PH-1 and Roadmap as tagged.

Where Formance wins — and when to choose it

Concessions first, without caveats.

  • Compliance today, not on a roadmap. SOC 2 Type II with a clean opinion, ISO 27001:2022 and a DORA assessment are issued and inspectable (their trust centre and security page, 2026-09-19). We target the same attestations inside PH-2 and cannot offer them today.
  • Payments connectivity as a product. Their connectivity layer normalises captures, refunds and payouts across a large connector set, with single-tenant private cloud and a 99.9% SLA. Ledgerbook does not move money and does not intend to.
  • Delivered enterprise self-host at scale. Operator, Helm charts, agent tooling and years of customer self-host deployments — a mature delivery track record Ledgerbook is still building toward.
  • Design-time tooling. Their free schema studio turns a business description into a versioned ledger schema with fixtures executed against a live ledger — a genuinely useful on-ramp.

How Ledgerbook differs — three things, no more

The accounting record layer

Ledgerbook models what financial statements need above money movement: multi-dimensional accounts, multi-entity consolidation with explicit paired intercompany entries, posted FX conversion and linked per-book valuations — the layer a payment ledger does not claim.

FR-126/128/131–134 · PH-1

Governed agent writes, not a read mirror

MCP is a first-class surface with HTTP parity, and the gate lives at the credential: agents propose, policy approves, the chain proves. The same governance holds in air-gapped deployments, which is where cloud-gated agent surfaces stop working.

FR-220/343 · PH-1 read/propose; full tool surface Roadmap

An audit export an auditor can run

OCEL 2.1 JSON out, a verifier that recomputes the chain and the balances from the export alone, and typed corrections that keep the original Final and independently verifiable. Evidence you can check beats evidence you must trust.

FR-905/121/123–125 · PH-1

Ask any ledger vendor these seven questions

The checklist behind this page — run it against us, and against anyone else on your shortlist.

  1. What is the immutability proof object — can a third party verify it without ledger access? ours: online and offline chain verification · PH-1
  2. What gate sits in front of agent writes, and can an agent credential approve or post? ours: proposal-only credentials · PH-1
  3. Where can the data legally run — self-host, BYOC, air-gap — and does the agent surface survive that deployment? ours: self-host and air-gap first-class · PH-1
  4. What export can an auditor take away, and can they load it independently? ours: OCEL 2.1 JSON + verifier · PH-1
  5. What happens after a Final entry turns out wrong — edit, delete, or typed correction? ours: typed corrections only — reversal, adjustment or restatement · PH-1
  6. How granular is access control — token, scope, row — and does it hold on exports too? ours: row-level, identical on every surface · PH-1
  7. What is shipped today versus Roadmap, and is every unshipped item labelled as such? ours: dated changelog · phase labels site-wide

Formance comparison FAQ

Are you saying Ledgerbook is better than Formance?

No. We are saying it is a different layer. Formance moves and reconciles money; Ledgerbook keeps the accounting record those movements roll up into. Their connectors, certifications and mature deployment tooling are real advantages in the payment-ledger problem, and this page names them. If your problem is rails, acceptance and PSP reconciliation, Formance is a direct fit.

Can we run Formance and Ledgerbook together?

Yes, and for many stacks that is the intended shape. Their exporters, event streams and API are a legitimate source-system path into Ledgerbook's ingestion contract — money movement below, the accounting book of record above. The two systems keep their own guarantees; Ledgerbook does not need to sit inside their deployment, or they inside ours.

What is the difference between a payment ledger and an accounting ledger?

A payment ledger records money movement — balances, transfers, settlements, holds — and exists to make value move correctly across rails. An accounting ledger is the book of record: double-entry postings, multi-entity consolidation, period states and typed corrections, built for financial statements and audit. Ledgerbook does not move money; it accounts for it. The two roles are complementary, which is why Formance's exporters are a legitimate ingestion source for the layer above.

Formance holds SOC 2 Type II, ISO 27001 and a DORA assessment. Ledgerbook holds none yet. Why look at us?

If certification today is a hard procurement requirement, choose a certified vendor — we say that plainly. Ledgerbook targets SOC 2 Type II and ISO 27001 inside PH-2, and until an attestation is issued we do not claim one. What we offer now is a verifiable audit surface: chain checks and OCEL 2.1 exports you can run yourself.

Formance's MCP server is read-only. What does Ledgerbook's do?

Ledgerbook's MCP surface carries read and propose tools, with semantics identical to HTTP — proposals land as provisional entries that policy must approve before the books move. The full tool surface, including approval-gated operational tools, is Roadmap. Both products keep models out of the posting path; the difference is that our MCP surface is part of the governed write path, not a read mirror.

Evaluate both, on the same axes

Design partners get the side-by-side pack — including the axes where we lose today.

Formance is the trademark of its owner and is used here as an adjective for comparison only; no logos, no implied endorsement or partnership. Every competitor claim above traces to a public source fetched on 2026-09-19 (dossiers 07 and 12, same date) and is re-verified quarterly. If a fact is wrong or stale, tell us and it is corrected and re-dated.