Security and readiness

Last reviewed: August 2026

Public readiness statement

This page describes the current product stage; it is not a certification, audit report, SLA, or substitute for a customer-specific security review. Security terms and deployment controls are agreed in writing for each engagement.

What we can support now

The initial customer offer is a fixed-scope crypto exposure assessment, designed to run inside a customer-approved environment without a hosted account.

  • Customer-controlled, read-only execution is the default delivery model
  • No production write access and no raw private keys are required
  • Finding snippets are redacted by default in the customer runner
  • The agreed scope, retention period, and deletion steps are documented before execution

Current assurance status

Independent penetration test
Not yet completed
SOC 2
Readiness work only; Latticis is not SOC 2 audited or certified
Hosted customer platform
Pre-production; customer accounts and public signup are not available
Post-quantum algorithms
Prototype support does not imply FIPS 140-3 or CMVP module validation
Operating controls
Policies and runbooks are being converted into tested operating evidence

Responsible disclosure

If you believe you found a vulnerability in a Latticis-owned system, send a concise description, reproduction steps, and potential impact. Do not include secrets or personal data, and do not test customer systems. We do not currently publish a response-time or remediation SLA.

security@latticis.com
Security and assurance boundaries | Latticis