Trust & Security
How LatticeUVW2x is built, scanned, and maintained. Last reviewed: 2026-09-13.
Compliance status
| Program | Status | Target |
|---|---|---|
| SOC 2 Type I | Readiness in progress | Q2 2027 |
| SOC 2 Type II | Planned | Post-Type-I |
| ISO 27001 | Not started | — |
| GDPR | Architecture supports data residency | — |
We do not display a SOC 2 badge until an audit report has been issued. Status language above reflects our actual position as of the review date.
Security program
Every release of LatticeUVW2x passes the following automated checks inside the development enclave. Source code is never uploaded to a third-party scanning service.
| Control | Tooling | Cadence |
|---|---|---|
| Static analysis (SAST) | Semgrep (OSS, self-hosted) | Every commit, every release |
| Secret & credential detection | Gitleaks | Every commit |
| Dependency CVE audit | pip-audit | Every release |
| Container hardening | Non-root UID, read-only root FS, dropped capabilities | Every image build |
| Kubernetes pod hardening | securityContext with allowPrivilegeEscalation: false | Every manifest change |
Latest security snapshot
Aggregate results from the most recent internal scan cycle. Raw scan output is retained internally as SOC 2 evidence but is not published (see "What we do not publish" below).
| Scan | Scope | Result |
|---|---|---|
| Static analysis | Product source | 0 unresolved critical / high (2 warnings — accepted or false positive) |
| Static analysis | Customer delivery package | 0 open findings |
| Secret scan | Product source | 0 leaks detected |
| Dependency audit | 3 Python projects | 0 known CVEs |
| Container hardening | Delivery compose + K8s manifests | Hardened |
Remediation history
| Snapshot | Date | Fix-now findings | Open |
|---|---|---|---|
| v2 | 2026-09-12 | 25 | — |
| v3 | 2026-09-13 | 0 | 0 |
Findings classified as "accepted with rationale" are documented internally with an explanation of why they present no material risk in the deployment model (e.g. development-only compose files that are not shipped).
Architecture privacy notes
- No telemetry. The product does not phone home, check for updates over the internet, or transmit usage data.
- No cloud callbacks. All runtime configuration, licensing, and policy are local. Licensing uses an offline-signed key file.
- No third-party analytics in the product. The marketing website uses only self-hosted, cookie-free measurement (or none).
- Scan tooling is offline. Semgrep, Gitleaks, and pip-audit run inside the development enclave against a pinned ruleset and a local vulnerability database.
- Signed releases. Release artifacts are accompanied by a SHA-256 manifest and (once enabled) a detached GPG signature.
Sub-processors
The LatticeUVW2x platform runs entirely on customer infrastructure. There are no sub-processors involved in the delivery or operation of the product.
| Category | Sub-processor | Purpose |
|---|---|---|
| Hosting | None — customer-hosted | — |
| Data processing | None — on-premises only | — |
| Analytics / telemetry | None | — |
| Email delivery (product) | None — no outbound mail in product | — |
Note: this website (latticeuvw.xyz) is hosted on Squarespace and uses Google Workspace for email. Neither has access to customer deployment data — they only serve the marketing site and business correspondence.
Vulnerability disclosure
We welcome reports from security researchers. Please send coordinated disclosure to the address below.
| Contact | security@latticeuvw.xyz |
|---|---|
| Encryption | PGP key available on request — first reply will include our public key |
| Acknowledgement SLA | 72 hours |
| Triage SLA | 30 days |
| Disclosure window | 90 days from triage (negotiable for critical issues) |
What we do not publish
We publish aggregate results and program controls, but we deliberately do not publish the following. This is standard practice and protects both our customers and our intellectual property.
- Raw scanner output, JSON reports, or SARIF files
- File paths, line numbers, or specific rule identifiers for any finding
- The content of scan exclusions (which files are in-scope vs out-of-scope)
- Internal remediation timelines or engineering tickets
- Source code, module inventory, or architecture diagrams
- Third-party dependency lists
- The identity of our external audit firm (until a signed report is issued)
These details are provided to procurement and security reviewers strictly under NDA. If you are evaluating LatticeUVW2x for enterprise deployment, please contact security@latticeuvw.xyz to request our pre-filled SIG Lite questionnaire or our Confidential Evidence Pack (which includes raw scanner outputs, exact file paths, and commit traces).
Questions
For security questionnaires, NDA-bound evidence requests, or general trust inquiries:
security@latticeuvw.xyz