Your client files hold payroll, margins, and the owner's worst quarter. The people evaluating Larch are accountants, and accountants check the support. So this page names systems, regions, and boundaries rather than gesturing at them.
Short answers a reviewer can paste into a vendor assessment. If an answer changes, this page changes the same week.
Last reviewed June 2026
Larch uses a language model inside the cycle. That deserves a precise answer, not a reassuring one. The boundary below is enforced in the product. It is not a usage guideline that depends on people behaving.
Every sentence a client reads was signed by a person at your firm. That is the whole policy, and the software enforces it.
A morning of activity on one engagement, as a firm admin sees it. Actor, timestamp, object. Decisions link to the actions that raised them, so the trail reads as a chain, not a pile.
Illustrative log · initials and IDs fabricated, format as shipped
The same engagement looks different depending on who opens it. These boundaries are structural, which matters more than any promise.
Sees the portal: published Packs, open decisions, and asks addressed to them. Never the Working Brief, never draft states, never another client.
Sees everything on their assigned engagements. Drafters draft; only the named reviewer can advance a review state.
Sees all engagements, the activity log, and connection settings. Cannot skip a review chain; admin is a scope, not an override.
No standing access to client financial data. Support access is granted by the firm, scoped to one engagement, time-boxed, and it shows up in the same log you read above.
Send the vendor questionnaire to security@uselarch.com. A person who can read it answers it, usually within two business days.