Security & Compliance
How we protect your data — the controls we enforce, our compliance posture, and how we monitor it continuously.
Compliance Posture
SOC 2
Controls implemented · MonitoredTrust Services Criteria controls in place, continuously monitored via Vanta. Type II report in progress.
GDPR
AlignedData-subject rights, data minimization, and processing records supported.
ISO 27001
In progressISMS controls being formalized ahead of certification audit.
HIPAA
EligibleTechnical safeguards available for covered workloads under BAA.
SOC 2 is an attestation issued by an independent auditor. We describe implemented controls and monitoring status here; a signed report is available to customers under NDA once the Type II observation period completes.
Controls We Enforce
Encryption at Rest & In Transit
Integration credentials are encrypted at rest with AES-256-GCM before storage; all traffic is served over TLS.
Access Control & Audit Logging
Role-based admin access with every privileged action written to an immutable audit log.
Tenant Isolation (RLS)
Row-Level Security policies scope every record to its owner, so customer data is never co-mingled.
Hashed API Keys
API keys are stored only as SHA-256 hashes — the raw key is shown once and never persisted.
Hardened HTTP Responses
HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy on every response.
Continuous Monitoring
Security controls are continuously evidenced and monitored through Vanta for SOC 2 readiness.
Data Handling
- Data is hosted on enterprise cloud infrastructure (Vercel & Supabase) in access-controlled facilities.
- Third-party integration tokens are encrypted before storage and decrypted only at point of use.
- You can disconnect any integration at any time, which revokes and deletes its stored credentials.
Report a Vulnerability
We take security seriously. If you discover a vulnerability, please report it responsibly and we'll respond promptly.
security@lattice.inc