Trust Center · evidence-led
The companies and code paths around Latchstead.
This register names vendors and integrations visible in the current checkout, then keeps the unknowns visible: status, data handled, region, purpose, source, and the boundary of what the repository can actually establish.
Evidence package
2026-08-29
Redacted repository and local-checkout evidence. No deployment, production, account, regional, certification, or independent compliance attestation is made.
How to read this register
Evidence, with its edges intact.
“Verified live” means the current checkout contains and uses the integration path. It is not an independent production, account, regional, certification, or compliance attestation. “Pending disclosure” means the repository does not establish enough about the provider, account, downstream processor, region, or production status.
Concrete current-checkout integration evidence; no broader operational claim.
A code or package reference exists, but owner/platform evidence is still required.
Vendor register
What the checkout shows
10 disclosed paths · evidence date 2026-08-29
Authentication
Data handled
Account credentials, profile identifiers, sessions, and authentication state.
Region
App/database hosting region — Not evidenced — owner input required.
Purpose
Email/password sign-in, session management, and the application admin role.
Evidence source
Installed better-auth module and src/lib/auth-config.ts.
Limitation
The code path is present; hashing implementation, deployment region, and operational account controls are not independently evidenced.
Billing
Data handled
Checkout details, customer email when supplied, payment status, and checkout identifiers.
Region
Stripe/provider account and processing region — Not evidenced — owner input required.
Purpose
Hosted checkout and payment-event verification for billing flows.
Evidence source
src/lib/stripe-billing/client.ts and installed stripe-billing module.
Limitation
The repository contains the proxy integration, but no payment-provider account export or confirmation that Stripe onboarding is enabled.
Hosting
Data handled
Application runtime data, database-resident app data, logs, and deployment artifacts.
Region
Deployment and database region — Not evidenced — owner input required.
Purpose
Run the Next.js application, startup migration, healthcheck, and provisioned database.
Evidence source
Render platform guide and polsia.toml deployment manifest.
Limitation
The platform path is documented, but the live service, account ownership, region, retention, and production configuration are not evidenced.
Analytics
Data handled
Page path, anonymous visitor ID, referrer, and user-agent data when analytics is configured.
Region
Analytics provider role, retention, and region — Not evidenced — owner input required.
Purpose
Page-load measurement and owner-facing site-visit aggregation.
Evidence source
Framework analytics beacon, src/app/layout.tsx, and src/app/api/site-visits/route.ts.
Limitation
The repository shows both paths, but it does not establish deployed configuration, provider roles, retention, or regional processing.
Data handled
Recipient addresses, message content, reply-to identifiers, and application-generated notifications.
Region
Proxy/downstream delivery region — Not evidenced — owner input required.
Purpose
Deliver transactional application email through the platform email proxy.
Evidence source
src/lib/email/send.ts and the application email template catalog.
Limitation
Application delivery code is present, but no provider account export, downstream provider name, region, or retention record was found.
PDF generation
Data handled
Document content supplied to the local renderer while a PDF is generated.
Region
Application runtime region — covered by hosting; no separate transfer evidenced.
Purpose
Generate lease, receipt, and other application PDFs without a remote document service.
Evidence source
src/lib/pdf/client.ts and pdf-lib dependency.
Limitation
This is a library/data-flow disclosure, not a remote sub-processor or a claim about hosting operations.
Internationalization
Data handled
Locale preference cookie and locally checked-in translation messages; no translation SaaS transfer evidenced.
Region
No separate vendor region; locale configuration and messages are local to the application.
Purpose
Cookie-based locale selection and rendering of localized interface copy.
Evidence source
Installed i18n module, src/i18n/config.ts, and checked-in messages/en.json.
Limitation
The local integration does not establish the hosting region or the operational posture of the application that serves the messages.
AI
Data handled
User prompts, application context, and generated responses sent through AI features.
Region
Proxy/model-provider region — Not evidenced — owner input required.
Purpose
Provide the installed AI chat and structured-output capability through a managed proxy.
Evidence source
Installed ai module, src/lib/ai/client.ts, and /api/ai/chat route.
Limitation
The application proxy path is present, but the evidence package has no provider/account export, production-use confirmation, or processing region.
Accounting integration
Data handled
Accounting connection identifiers, OAuth tokens, company metadata, and application accounting records sent to the integration.
Region
Intuit account, sandbox/production environment, and processing region — Not evidenced — owner input required.
Purpose
Connect the owner-facing accounting workflow to QuickBooks Online.
Evidence source
QuickBooks schema/client/OAuth code, owner-only routes, and focused tests in the evidence package.
Limitation
The checkout contains sandbox integration code and tests; it does not establish production credentials, deployment, Intuit approval, or live account/region status.
File storage
Data handled
Uploaded receipts, generated PDF bytes, file names, and returned storage URLs/keys.
Region
Storage account and region — Not evidenced — owner input required.
Purpose
Upload receipt and PDF files from server routes through the authenticated platform proxy.
Evidence source
src/lib/uploads/r2.ts and src/lib/uploads/pdf-bytes.ts.
Limitation
The upload path is concrete, but the downstream provider, account, retention, access controls, and region are not established by the checkout.
This page is a dated repository disclosure, not a complete legal sub-processor notice or a promise that every listed path is enabled in production. Provider accounts, downstream processors, regions, retention, and operational controls remain pending wherever the evidence package does not establish them. Xero is not listed because the package identifies it as product-copy-only, not a found live integration.
Back to the Trust Center