Trust Center · evidence-led
What we can show, and where the record stops.
This page describes Latchstead security from a dated evidence package, not from broad promises. Specific repository observations are separated from the production and operational questions that still need owner or platform confirmation.
Evidence boundary
August 29, 2026
Redacted repository and local-checkout evidence. It does not attest deployment, production or end-to-end validation, completed review, vendor/account controls, certification, or Intuit approval.
Evidence categories
A map of what is available.
The underlying register is not a public download. These summaries keep its scope visible while the policy pages provide the public routes for questions and reports.
The package records focused observations, not complete testing or public evidence access.
The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.
Owner or platform evidence is required before the inventory can be completed.
Completion requires owner or platform evidence, confirmation, or an operational decision.
The reporting path is public, but the incident plan and response-time decision remain owner-dependent.
Completion requires owner or platform evidence, confirmation, or an operational decision.
Evidence publication
Latest tabletop and restoration record
Only completed records with approved review and a clear completion projection appear with dates and outcomes. Other records remain explicitly unpublished here.
Claim ledger
Observation, source, limitation.
Every statement below is intentionally narrow. “Observed” means seen in the dated checkout or focused test record; it does not mean deployed, comprehensive, or approved.
This is a dated repository observation, not proof of deployment or operational control.
The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.
Observation
The inspected QBO schema and cipher implement intended encrypted token fields with versioned AES-256-GCM handling.
Source and date
Credential-storage review · 2026-08-29
Limitation
Repository evidence only. Key custody, rotation, backup treatment, and production values were not evidenced.
The focused code and test observations do not establish production approval or coverage.
The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.
Observation
The inspected OAuth boundary hashes persisted state, checks expiry/replay, requests the Accounting scope, and maps provider failures to bounded codes.
Source and date
Credential-storage review and focused QBO tests · 2026-08-29
Limitation
Focused code/test evidence only. No production OAuth trace, vendor-side access review, or Intuit approval was evidenced.
The observed code path does not establish a complete production access review.
The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.
Observation
The package records admin-gated QBO routes and a focused test for rejection of non-admin access.
Source and date
Access-control review · 2026-08-29
Limitation
This supports a code-path observation, not a complete production access inventory, MFA review, or least-privilege conclusion.
The dated test record exists, while blocked and unresolved checks remain visible.
The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.
Observation
Focused QBO OAuth and route tests are listed as repository evidence, alongside a limited non-test secret-pattern scan.
Source and date
Test results · 2026-08-29
Limitation
The package records blocked or unresolved dependency, staging, isolation, backup/restore, and full-validation checks. It is not a testing pass.
Public policy surfaces
Start with the question you have.
These are the available public pages. The evidence register itself stays private and redacted; it should not be treated as a certification, production attestation, or approval record.
The index separates repository observations from pending exercises, production questions, and legal review.
This policy or legal copy awaits counsel review and is not final legal advice.
The dated public register exists, but its cards retain unresolved owner and legal caveats.
The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.
The public index exists; individual policy records retain their own draft or owner-dependent status.
The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.
Public draft exists; owner confirmation and legal review remain pending. It makes no promise about monitoring, response timing, investigation, or enforcement outcomes.
Working content that is not final.
Owner confirmation and legal review remain pending; the page is not an executed DPA or a complete production subprocessor record.
Working content that is not final.
The register is repository-backed; provider, account, region, and production details remain pending where not evidenced.
Completion requires owner or platform evidence, confirmation, or an operational decision.
Independent testing and remediation remain pending; the template does not claim completed testing, findings, or coverage.
The proposed exercise or retest has not yet been run or evidenced.
The exercise has not been run or evidenced; all result fields remain owner input.
The proposed exercise or retest has not yet been run or evidenced.
The owner-conducted exercise has not been run or evidenced; all outcome fields remain owner input.
The proposed exercise or retest has not yet been run or evidenced.
Owner confirmation and legal review remain pending as of the 2026-09-06 evidence boundary.
Working content that is not final.
The 0.1-draft remains owner-dependent pending owner confirmation and legal review.
Working content that is not final.
A public contact path exists; response handling and timing depend on the owner.
Completion requires owner or platform evidence, confirmation, or an operational decision.
Stories remain private until explicit permission and owner publication.
Completion requires owner or platform evidence, confirmation, or an operational decision.
Only complete records with explicit consent and owner review appear in the public library.
Completion requires owner or platform evidence, confirmation, or an operational decision.
The page intentionally shows an honest empty state until an approved, consented record is available.
Completion requires owner or platform evidence, confirmation, or an operational decision.
All amounts are illustrative; final pricing and checkout remain pending published case-study validation.
Completion requires owner or platform evidence, confirmation, or an operational decision.
The FAQ describes intended or early-access workflows and does not certify compliance, coverage, or provider approval.
Completion requires owner or platform evidence, confirmation, or an operational decision.
Security reporting
Have a question the evidence does not answer?
Use the public contact route for a security report or a request for clarification. No fixed response-time SLA is promised here because a completed incident-response plan was not evidenced in the 2026-08-29 package.