Trust & Security

How LatticeUVW2x is built, scanned, and maintained. Last reviewed: 2026-09-13.

Built for air-gapped and on-prem deployments. LatticeUVW2x is designed for regulated industries — defense, finance, government — where data cannot leave the customer's perimeter. There is no telemetry, no cloud callback, and no third-party analytics in the product.

Compliance status

ProgramStatusTarget
SOC 2 Type IReadiness in progressQ2 2027
SOC 2 Type IIPlannedPost-Type-I
ISO 27001Not started—
GDPRArchitecture supports data residency—

We do not display a SOC 2 badge until an audit report has been issued. Status language above reflects our actual position as of the review date.

Security program

Every release of LatticeUVW2x passes the following automated checks inside the development enclave. Source code is never uploaded to a third-party scanning service.

ControlToolingCadence
Static analysis (SAST)Semgrep (OSS, self-hosted)Every commit, every release
Secret & credential detectionGitleaksEvery commit
Dependency CVE auditpip-auditEvery release
Container hardeningNon-root UID, read-only root FS, dropped capabilitiesEvery image build
Kubernetes pod hardeningsecurityContext with allowPrivilegeEscalation: falseEvery manifest change

Latest security snapshot

Aggregate results from the most recent internal scan cycle. Raw scan output is retained internally as SOC 2 evidence but is not published (see "What we do not publish" below).

ScanScopeResult
Static analysisProduct source0 unresolved critical / high (2 warnings — accepted or false positive)
Static analysisCustomer delivery package0 open findings
Secret scanProduct source0 leaks detected
Dependency audit3 Python projects0 known CVEs
Container hardeningDelivery compose + K8s manifestsHardened

Remediation history

SnapshotDateFix-now findingsOpen
v22026-09-1225—
v32026-09-1300

Findings classified as "accepted with rationale" are documented internally with an explanation of why they present no material risk in the deployment model (e.g. development-only compose files that are not shipped).

Architecture privacy notes

  • No telemetry. The product does not phone home, check for updates over the internet, or transmit usage data.
  • No cloud callbacks. All runtime configuration, licensing, and policy are local. Licensing uses an offline-signed key file.
  • No third-party analytics in the product. The marketing website uses only self-hosted, cookie-free measurement (or none).
  • Scan tooling is offline. Semgrep, Gitleaks, and pip-audit run inside the development enclave against a pinned ruleset and a local vulnerability database.
  • Signed releases. Release artifacts are accompanied by a SHA-256 manifest and (once enabled) a detached GPG signature.

Sub-processors

The LatticeUVW2x platform runs entirely on customer infrastructure. There are no sub-processors involved in the delivery or operation of the product.

CategorySub-processorPurpose
HostingNone — customer-hosted—
Data processingNone — on-premises only—
Analytics / telemetryNone—
Email delivery (product)None — no outbound mail in product—

Note: this website (latticeuvw.xyz) is hosted on Squarespace and uses Google Workspace for email. Neither has access to customer deployment data — they only serve the marketing site and business correspondence.

Vulnerability disclosure

We welcome reports from security researchers. Please send coordinated disclosure to the address below.

Contactsecurity@latticeuvw.xyz
EncryptionPGP key available on request — first reply will include our public key
Acknowledgement SLA72 hours
Triage SLA30 days
Disclosure window90 days from triage (negotiable for critical issues)

What we do not publish

We publish aggregate results and program controls, but we deliberately do not publish the following. This is standard practice and protects both our customers and our intellectual property.

  • Raw scanner output, JSON reports, or SARIF files
  • File paths, line numbers, or specific rule identifiers for any finding
  • The content of scan exclusions (which files are in-scope vs out-of-scope)
  • Internal remediation timelines or engineering tickets
  • Source code, module inventory, or architecture diagrams
  • Third-party dependency lists
  • The identity of our external audit firm (until a signed report is issued)

These details are provided to procurement and security reviewers strictly under NDA. If you are evaluating LatticeUVW2x for enterprise deployment, please contact security@latticeuvw.xyz to request our pre-filled SIG Lite questionnaire or our Confidential Evidence Pack (which includes raw scanner outputs, exact file paths, and commit traces).

Questions

For security questionnaires, NDA-bound evidence requests, or general trust inquiries:

security@latticeuvw.xyz