Skip to content

Trust Center · evidence-led

The companies and code paths around Latchstead.

This register names vendors and integrations visible in the current checkout, then keeps the unknowns visible: status, data handled, region, purpose, source, and the boundary of what the repository can actually establish.

Evidence package

2026-08-29

Redacted repository and local-checkout evidence. No deployment, production, account, regional, certification, or independent compliance attestation is made.

How to read this register

Evidence, with its edges intact.

“Verified live” means the current checkout contains and uses the integration path. It is not an independent production, account, regional, certification, or compliance attestation. “Pending disclosure” means the repository does not establish enough about the provider, account, downstream processor, region, or production status.

verified live

Concrete current-checkout integration evidence; no broader operational claim.

pending disclosure

A code or package reference exists, but owner/platform evidence is still required.

Vendor register

What the checkout shows

10 disclosed paths · evidence date 2026-08-29

Authentication

verified live
Better Auth, self-hosted in the Latchstead app

Data handled

Account credentials, profile identifiers, sessions, and authentication state.

Region

App/database hosting region — Not evidenced — owner input required.

Purpose

Email/password sign-in, session management, and the application admin role.

Evidence source

Installed better-auth module and src/lib/auth-config.ts.

Limitation

The code path is present; hashing implementation, deployment region, and operational account controls are not independently evidenced.

Billing

pending disclosure
Stripe through the Polsia company-payments proxy

Data handled

Checkout details, customer email when supplied, payment status, and checkout identifiers.

Region

Stripe/provider account and processing region — Not evidenced — owner input required.

Purpose

Hosted checkout and payment-event verification for billing flows.

Evidence source

src/lib/stripe-billing/client.ts and installed stripe-billing module.

Limitation

The repository contains the proxy integration, but no payment-provider account export or confirmation that Stripe onboarding is enabled.

Hosting

pending disclosure
Render / Polsia deployment platform

Data handled

Application runtime data, database-resident app data, logs, and deployment artifacts.

Region

Deployment and database region — Not evidenced — owner input required.

Purpose

Run the Next.js application, startup migration, healthcheck, and provisioned database.

Evidence source

Render platform guide and polsia.toml deployment manifest.

Limitation

The platform path is documented, but the live service, account ownership, region, retention, and production configuration are not evidenced.

Analytics

pending disclosure
Polsia analytics beacon plus Latchstead /api/site-visits path

Data handled

Page path, anonymous visitor ID, referrer, and user-agent data when analytics is configured.

Region

Analytics provider role, retention, and region — Not evidenced — owner input required.

Purpose

Page-load measurement and owner-facing site-visit aggregation.

Evidence source

Framework analytics beacon, src/app/layout.tsx, and src/app/api/site-visits/route.ts.

Limitation

The repository shows both paths, but it does not establish deployed configuration, provider roles, retention, or regional processing.

Email

pending disclosure
Polsia email proxy; downstream delivery provider not named in the checkout

Data handled

Recipient addresses, message content, reply-to identifiers, and application-generated notifications.

Region

Proxy/downstream delivery region — Not evidenced — owner input required.

Purpose

Deliver transactional application email through the platform email proxy.

Evidence source

src/lib/email/send.ts and the application email template catalog.

Limitation

Application delivery code is present, but no provider account export, downstream provider name, region, or retention record was found.

PDF generation

verified live
pdf-lib, local in-process document generation

Data handled

Document content supplied to the local renderer while a PDF is generated.

Region

Application runtime region — covered by hosting; no separate transfer evidenced.

Purpose

Generate lease, receipt, and other application PDFs without a remote document service.

Evidence source

src/lib/pdf/client.ts and pdf-lib dependency.

Limitation

This is a library/data-flow disclosure, not a remote sub-processor or a claim about hosting operations.

Internationalization

verified live
next-intl with checked-in message dictionaries

Data handled

Locale preference cookie and locally checked-in translation messages; no translation SaaS transfer evidenced.

Region

No separate vendor region; locale configuration and messages are local to the application.

Purpose

Cookie-based locale selection and rendering of localized interface copy.

Evidence source

Installed i18n module, src/i18n/config.ts, and checked-in messages/en.json.

Limitation

The local integration does not establish the hosting region or the operational posture of the application that serves the messages.

AI

pending disclosure
Polsia AI proxy; downstream model provider not named in the checkout

Data handled

User prompts, application context, and generated responses sent through AI features.

Region

Proxy/model-provider region — Not evidenced — owner input required.

Purpose

Provide the installed AI chat and structured-output capability through a managed proxy.

Evidence source

Installed ai module, src/lib/ai/client.ts, and /api/ai/chat route.

Limitation

The application proxy path is present, but the evidence package has no provider/account export, production-use confirmation, or processing region.

Accounting integration

pending disclosure
QuickBooks Online / Intuit sandbox OAuth integration

Data handled

Accounting connection identifiers, OAuth tokens, company metadata, and application accounting records sent to the integration.

Region

Intuit account, sandbox/production environment, and processing region — Not evidenced — owner input required.

Purpose

Connect the owner-facing accounting workflow to QuickBooks Online.

Evidence source

QuickBooks schema/client/OAuth code, owner-only routes, and focused tests in the evidence package.

Limitation

The checkout contains sandbox integration code and tests; it does not establish production credentials, deployment, Intuit approval, or live account/region status.

File storage

pending disclosure
Polsia R2 upload proxy; downstream storage provider not named in the checkout

Data handled

Uploaded receipts, generated PDF bytes, file names, and returned storage URLs/keys.

Region

Storage account and region — Not evidenced — owner input required.

Purpose

Upload receipt and PDF files from server routes through the authenticated platform proxy.

Evidence source

src/lib/uploads/r2.ts and src/lib/uploads/pdf-bytes.ts.

Limitation

The upload path is concrete, but the downstream provider, account, retention, access controls, and region are not established by the checkout.

Disclosure boundary

This page is a dated repository disclosure, not a complete legal sub-processor notice or a promise that every listed path is enabled in production. Provider accounts, downstream processors, regions, retention, and operational controls remain pending wherever the evidence package does not establish them. Xero is not listed because the package identifies it as product-copy-only, not a found live integration.

Back to the Trust Center