Security

Specifics, because trust us is not an answer.

Your client files hold payroll, margins, and the owner's worst quarter. The people evaluating Larch are accountants, and accountants check the support. So this page names systems, regions, and boundaries rather than gesturing at them.

This page avoids vague phrases like bank-grade or autonomous finance.
Where we cannot be specific yet, the line below says so.
Where things live

The facts, in one column.

Short answers a reviewer can paste into a vendor assessment. If an answer changes, this page changes the same week.

Last reviewed June 2026

Hosting and region Supabase Postgres in ca-central-1 (Montréal). Client financial data does not leave the Canadian region.
Tenancy Firm-scoped isolation enforced at the database row level. A firm's queries cannot return another firm's rows, even with an application bug, because the policy sits below the application.
Encryption TLS 1.2 or higher in transit. AES-256 at rest, managed by the platform provider.
Accounting connections Read-only, via OAuth where the provider supports it. Larch holds no credentials that can post to a client's books. Connections can be revoked from either side.
Access control Role-based per engagement: drafter, reviewer, signer, client. Roles are enforced by the system, not by convention. Two distinct people minimum on every review chain.
Audit logging Every state change on an engagement is logged with actor, timestamp, and object ID. The log is append-only and visible to firm admins.
Certifications SOC 2 Type II is in progress with an external auditor; the observation window closes Q4 2026. Until the report exists, we will not claim it. Ask and we will share the current controls memo.
The AI boundary

What the AI can do, and what it cannot.

Larch uses a language model inside the cycle. That deserves a precise answer, not a reassuring one. The boundary below is enforced in the product. It is not a usage guideline that depends on people behaving.

The AI can
  • +Draft KPI observations against the close data, for a person to keep, edit, or kill.
  • +Propose a first draft of the Working Brief from signed observations.
  • +Flag rows that fail tie-out and suggest a likely mapping.
  • +Summarize a forecast delta between two locked versions.
The AI cannot
  • Publish anything a client sees. Every client-visible surface requires a named human sign-off.
  • Modify close data, post entries, or touch the books in any direction.
  • Lock a forecast version or record a decision.
  • Train on your client data. Engagement data is not used to train models, ours or anyone's.

Every sentence a client reads was signed by a person at your firm. That is the whole policy, and the software enforces it.

The audit trail

What the log actually looks like.

A morning of activity on one engagement, as a firm admin sees it. Actor, timestamp, object. Decisions link to the actions that raised them, so the trail reads as a chain, not a pile.

Activity · Westmount MechanicalJun 11 · append-only
08:42:11 EDTRK · Forecast v3 locked. v2 retained on record.
09:15:03 EDTAI draft · 3 observations proposed against KPI-06. Status: unreviewed.
09:31:47 EDTDM · Observation OBS-118 edited and kept. OBS-119 killed.
10:04:29 EDTDM · Decision DEC-042 recorded. Linked to action ACT-019.
11:58:50 EDTRK · Working Brief moved to Final review. Signer: RK.

Illustrative log · initials and IDs fabricated, format as shipped

Who sees what

Four roles, and the lines between them.

The same engagement looks different depending on who opens it. These boundaries are structural, which matters more than any promise.

The client

Sees the portal: published Packs, open decisions, and asks addressed to them. Never the Working Brief, never draft states, never another client.

The engagement team

Sees everything on their assigned engagements. Drafters draft; only the named reviewer can advance a review state.

The firm admin

Sees all engagements, the activity log, and connection settings. Cannot skip a review chain; admin is a scope, not an override.

Larch staff

No standing access to client financial data. Support access is granted by the firm, scoped to one engagement, time-boxed, and it shows up in the same log you read above.

Your reviewer will have questions this page did not answer.

Send the vendor questionnaire to security@uselarch.com. A person who can read it answers it, usually within two business days.

security@uselarch.com