Security at Lar.
Your portfolio’s financial, tenancy and compliance records are sensitive. This is how we protect them, in plain language.
Organisation isolation
Every record belongs to your organisation, isolated by row-level security at the database. Access checks run on the server for every query.
Encryption everywhere
Data is encrypted in transit with TLS and at rest on our infrastructure. There is no unencrypted path between your browser and your records.
Two-factor authentication
TOTP two-factor authentication is available on every account, using the authenticator app you already have. We recommend turning it on from day one.
UK GDPR
Application data is stored in the EU and we collect only what the product needs. The privacy policy sets out the detail without padding.
Your data is yours
Export your records at any time, including the accountant pack. If you leave Lar, your data leaves with you in formats another system can read.
Responsible disclosure
Found a vulnerability? Tell us at hello@uselar.com. We respond quickly, fix it with you and credit you if you like. No legal threats for good-faith research.
Who processes your data
We keep the vendor list short and name every processor in the privacy policy: Supabase (database and authentication, EU hosted), Stripe (payments), Plausible (cookieless analytics), Cal.com (scheduling) and Meta (advertising measurement, only with your consent, with the same events also passing through Meta’s Conversions API Gateway relay). Each is bound by its own data processing agreement.
What we do not claim
Lar does not hold SOC 2 or ISO 27001 certification, and we will not put badges on this page we have not earned. Formal certification is on the roadmap as the company grows. Until then, this page describes the controls that are in place.
Questions
If your accountant, lender or IT adviser has security questions before you bring portfolio data into Lar, write to hello@uselar.com and we will answer them directly.