Ledgerhaus Technologies GmbH
Cloud accounting software for tax advisors · Frankfurt am Main · 85 (product and operations) employees
Accounting SaaS properties on Pro-tier telemetry and log sync so operations can evidence backup schedules without a full-time SRE hire.
- RPO
- 5 minutes (WAL archive); daily full backup retained 30 days
- RTO
- 1 hour for failover to the synchronous replica; 4 hours for PITR to a new instance
- SLA
- Pro tier: log aggregation and backup schedule telemetry; priority email within 8 business hours
Situation
Ledgerhaus sells to Steuerberater practices and needed SOC 2 Type I evidence in Q2 2026 for a bank-channel partnership. The application was stable, but slow reporting queries blocked the primary, backups had never been restored, and there was no named owner for access reviews or patch evidence.
Environment
- Region and placement
- Managed Kubernetes and PostgreSQL in eu-central-1; object storage in eu-central-1
- Hosts
- 12 worker nodes; 1 PostgreSQL primary + 1 synchronous replica; 3 Redis nodes
- Operating systems and runtime
- Bottlerocket on EKS; PostgreSQL 16 on RDS-equivalent managed instances operated by Veltis
- Data stores
- 1.1 TB tenant data; 90 GB daily WAL
- Connectivity and access
- Private link from the application VPC; GitHub OIDC to the cluster; no standing human SSH
Agreed scope
- Named engineer, custom SLA, and 24/7 incident telephone
- Database performance programme and capacity plan through 2027
- Daily backups, point-in-time recovery window of 7 days, quarterly restore evidence
- Access reviews, CIS-aligned node hardening, and evidence folders for the SOC 2 auditor
Work performed
- Identified three reporting queries without tenant_id predicates; added covering indexes and a read replica for BI.
- Primary CPU p95 fell from 84% to 31% during month-end close; statement timeout policy introduced at 30 s.
- Configured continuous WAL archiving and ran a PITR drill to a forked instance (restore to 16:40 CET, 22 minutes).
- Removed long-lived cloud keys; engineers assume roles via OIDC with 4-hour sessions and a ticket ID in the audit trail.
- Delivered the infrastructure evidence pack (access, change, backup, incident) used in the June 2026 SOC 2 Type I report.
Measured results
Month-end primary CPU p95
31% (from 84%)
PITR drill
22 minutes
SOC 2 Type I (infra controls)
Issued June 2026
Standing SSH keys
0
Service tier: Distributed Node Telemetry & Log Sync. Commercial inquiries: contact operations.