Security at Lar
Your portfolio's financial, tenancy, and compliance records are sensitive. Here is exactly how we protect them, in plain language.
Organisation isolation
Every record in Lar belongs to your organisation and is isolated with row-level security enforced at the database layer. Access checks run on the server for every query, not just in the interface.
Encryption everywhere
Data is encrypted in transit with TLS and encrypted at rest on our infrastructure. There is no unencrypted path between your browser and your data.
Two-factor authentication
TOTP-based two-factor authentication is available on every account, using the authenticator app you already have. We recommend enabling it from day one.
UK GDPR
Lar is built for UK GDPR compliance. Application data is stored in the EU, we collect only what the product needs, and our privacy policy sets out the detail without legal padding.
Your data is yours
Export your records at any time, including the structured accountant pack. If you leave Lar, your data leaves with you, in formats another system can read.
Responsible disclosure
Found a vulnerability? Tell us at hello@uselar.com and we will respond quickly, work with you on a fix, and credit you if you want it. No legal threats for good-faith research.
Who processes your data
We keep our vendor list short and name every processor in the privacy policy: Supabase (database and authentication, EU hosted), Stripe (payments), Plausible (privacy-friendly analytics, no cookies), Formspree (form submissions), and Cal.com (scheduling). Each is bound by its own data processing agreement.
What we do not claim
Lar does not currently hold SOC 2 or ISO 27001 certification, and we will not put badges on this page that we have not earned. As the company grows, formal certification is on the roadmap; until then, this page describes the controls that are actually in place.
Questions
If your accountant, lender, or IT adviser has security questions before you bring portfolio data into Lar, write to hello@uselar.com and we will answer them directly.