Skip to content

Trust Center · evidence-led

What we can show, and where the record stops.

This page describes Latchstead security from a dated evidence package, not from broad promises. Specific repository observations are separated from the production and operational questions that still need owner or platform confirmation.

Evidence boundary

August 29, 2026

Redacted repository and local-checkout evidence. It does not attest deployment, production or end-to-end validation, completed review, vendor/account controls, certification, or Intuit approval.

Evidence categories

A map of what is available.

The underlying register is not a public download. These summaries keep its scope visible while the policy pages provide the public routes for questions and reports.

Testing scope and results
The dated package records local dependency, secret-pattern, static-analysis, and focused OAuth/access-control checks. Several environment checks were not run.
Evidence-backed

The package records focused observations, not complete testing or public evidence access.

The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.

Vendor and access inventory
The inventory identifies owner, role, MFA, and keep/revoke fields as unresolved where no account export was available. No vendor or production access conclusion is inferred.
Owner-dependent

Owner or platform evidence is required before the inventory can be completed.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Security reports and response
Security concerns can be sent through the public reporting path. A completed incident-response plan or response-time SLA was not evidenced in the package.
Owner-dependent

The reporting path is public, but the incident plan and response-time decision remain owner-dependent.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Read the reporting path

Evidence publication

Latest tabletop and restoration record

Only completed records with approved review and a clear completion projection appear with dates and outcomes. Other records remain explicitly unpublished here.

Loading publication summary…

Claim ledger

Observation, source, limitation.

Every statement below is intentionally narrow. “Observed” means seen in the dated checkout or focused test record; it does not mean deployed, comprehensive, or approved.

QuickBooks token storage
Evidence-backed

This is a dated repository observation, not proof of deployment or operational control.

The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.

Observation

The inspected QBO schema and cipher implement intended encrypted token fields with versioned AES-256-GCM handling.

Source and date

Credential-storage review · 2026-08-29

Limitation

Repository evidence only. Key custody, rotation, backup treatment, and production values were not evidenced.

OAuth state and provider scope
Evidence-backed

The focused code and test observations do not establish production approval or coverage.

The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.

Observation

The inspected OAuth boundary hashes persisted state, checks expiry/replay, requests the Accounting scope, and maps provider failures to bounded codes.

Source and date

Credential-storage review and focused QBO tests · 2026-08-29

Limitation

Focused code/test evidence only. No production OAuth trace, vendor-side access review, or Intuit approval was evidenced.

Administrative access
Evidence-backed

The observed code path does not establish a complete production access review.

The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.

Observation

The package records admin-gated QBO routes and a focused test for rejection of non-admin access.

Source and date

Access-control review · 2026-08-29

Limitation

This supports a code-path observation, not a complete production access inventory, MFA review, or least-privilege conclusion.

Testing and validation
Evidence-backed

The dated test record exists, while blocked and unresolved checks remain visible.

The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.

Observation

Focused QBO OAuth and route tests are listed as repository evidence, alongside a limited non-test secret-pattern scan.

Source and date

Test results · 2026-08-29

Limitation

The package records blocked or unresolved dependency, staging, isolation, backup/restore, and full-validation checks. It is not a testing pass.

Public policy surfaces

Start with the question you have.

These are the available public pages. The evidence register itself stays private and redacted; it should not be treated as a certification, production attestation, or approval record.

Security evidence index
Browse the dated security-evidence register, pending exercises, owner confirmations, and public reporting path.
Legal review required

The index separates repository observations from pending exercises, production questions, and legal review.

This policy or legal copy awaits counsel review and is not final legal advice.

Policy pack
Review each requested artifact category, its date, status, and open caveats.
Evidence-backed

The dated public register exists, but its cards retain unresolved owner and legal caveats.

The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.

Policies
Browse the dated policy-document index, including publication versions and visible review gaps.
Evidence-backed

The public index exists; individual policy records retain their own draft or owner-dependent status.

The dated artifact or observation exists; this does not mean certification, deployment, approval, or a passed review.

Acceptable Use Policy
Read the dated working draft for responsible use of landlord and tenant workflows and its open review boundary.
Draft

Public draft exists; owner confirmation and legal review remain pending. It makes no promise about monitoring, response timing, investigation, or enforcement outcomes.

Working content that is not final.

Data Processing Addendum
Read the bilingual 0.1-draft for processing roles, data categories, provider and transfer boundaries, security, requests, audits, and deletion.
Draft

Owner confirmation and legal review remain pending; the page is not an executed DPA or a complete production subprocessor record.

Working content that is not final.

Vendors & Sub-processors
See the vendors and integration paths evidenced in the checkout, with data, region, purpose, and status.
Owner-dependent

The register is repository-backed; provider, account, region, and production details remain pending where not evidenced.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Independent testing summary
Review the dated pending template for independent testing, remediation, and the evidence still required before any assessment claim.
Pending exercise

Independent testing and remediation remain pending; the template does not claim completed testing, findings, or coverage.

The proposed exercise or retest has not yet been run or evidenced.

Backup and restore evidence template
Open the dated owner-fillable record for a future backup-restore exercise and its evidence boundary.
Pending exercise

The exercise has not been run or evidenced; all result fields remain owner input.

The proposed exercise or retest has not yet been run or evidenced.

Incident-response tabletop evidence template
Open the dated owner-fillable record for the pending incident-response tabletop exercise and its evidence boundary.
Pending exercise

The owner-conducted exercise has not been run or evidenced; all outcome fields remain owner input.

The proposed exercise or retest has not yet been run or evidenced.

Privacy Notice
Read the dated draft covering information handled, use, sharing boundaries, retention principles, rights, and contact.
Draft

Owner confirmation and legal review remain pending as of the 2026-09-06 evidence boundary.

Working content that is not final.

Terms of Service
Review the dated 0.1-draft for service scope, pilot status, account use, limitations, termination, and contact.
Draft

The 0.1-draft remains owner-dependent pending owner confirmation and legal review.

Working content that is not final.

Contact
Ask a question or report a concern through the public contact route.
Owner-dependent

A public contact path exists; response handling and timing depend on the owner.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Case studies
Review published pilot stories and submit a consented story for moderation.
Owner-dependent

Stories remain private until explicit permission and owner publication.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Verified case-study library
Read complete, consented pilot records with the publication date and reviewing owner visible.
Owner-dependent

Only complete records with explicit consent and owner review appear in the public library.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Approved first-pilot feedback
Read pilot feedback only after explicit consent, publication approval, and authorized reviewer verification.
Owner-dependent

The page intentionally shows an honest empty state until an approved, consented record is available.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Illustrative pricing
Review the three planning tiers, comparison matrix, and the boundary around an offer that is not yet validated by published case studies.
Owner-dependent

All amounts are illustrative; final pricing and checkout remain pending published case-study validation.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Landlord FAQ
Get practical answers about screening, rent nudges, maintenance handoffs, integrations, pilot access, and data boundaries.
Owner-dependent

The FAQ describes intended or early-access workflows and does not certify compliance, coverage, or provider approval.

Completion requires owner or platform evidence, confirmation, or an operational decision.

Security reporting

Have a question the evidence does not answer?

Use the public contact route for a security report or a request for clarification. No fixed response-time SLA is promised here because a completed incident-response plan was not evidenced in the 2026-08-29 package.