Skip to content

Security

Protecting your business records.

Larder separates business records, checks access by role and records key operational changes. We can walk through the current controls and their limits with your team.

Separation between businesses

Larder checks which business a request belongs to before reading or changing its records. Data access is scoped to that business, with these controls treated as critical parts of every relevant change.

Access by responsibility

Roles and permissions determine which protected areas a person can use. Access is configured around responsibilities, and standard permissions are checked when the application starts.

Operational audit records

Key changes record who acted, which business and record were affected, and when. Some workflows also retain the values before and after the change, so authorised teams can review what happened.

Data in transit & at rest

TLS protects production traffic in transit and the managed PostgreSQL service provides encryption at rest. Production secrets are supplied through deployment secret management rather than application source files.

Hosting and software changes

Hosted on Replit's managed infrastructure. Software changes undergo review, automated checks and security checks before release, followed by checks that the published service works.

Compliance posture

Larder is designed to support UK food-business traceability and HACCP record-keeping workflows. We discuss each customer's regulatory and assurance requirements during implementation.

Doing diligence?

We're happy to walk through how access is controlled, how businesses are separated, and the current backup, recovery and audit arrangements.