Executive Summary
AI-generated analysis for Lattice
Lattice (lattice.com) is an HR and people management SaaS platform assessed at Risk Tier 4 (Low Risk) with a 94% confidence score, reflecting a strong overall security and compliance posture appropriate for medium data access engagements. Lattice demonstrates several meaningful positive signals across the investigation:
Key Findings
- The domain is 29+ years established with a clean threat intelligence profile: zero abuse reports, no malware or phishing flags, no adverse media in either recent or historical searches, and no sanctions exposure.
- Infrastructure is protected by Cloudflare CDN, with a 0% IP abuse score and a clean Malware detection service status.
- The vendor publicly claims SOC 2, GDPR, and CCPA compliance on its trust page (https://lattice.com/security), and its SOC 2 compliance posture is managed through the Drata platform — a positive operational signal.
- Lattice explicitly commits to not training AI models on customer data, and discloses the use of OpenAI and Anthropic as third-party AI providers — demonstrating meaningful transparency in an area of growing regulatory scrutiny.
- No FDIC, SEC enforcement, or sanctions concerns were identified; all such searches returned clean results as expected for a SaaS vendor. Two areas warrant follow-up before onboarding is finalized. First, 13 open ports are visible on Lattice's external infrastructure. All are consistent with Cloudflare-proxied services (alternate HTTP/HTTPS ports), and no CVEs were detected, but the count is above the typical SaaS baseline and merits a brief inquiry. Second, SOC 2, GDPR, and CCPA certifications are vendor-attested only — no independent registry confirmation was possible, which is expected given the nature of these frameworks, but the actual SOC 2 Type II report and bridge letter should be obtained prior to finalizing the vendor relationship. An unconfirmed HITRUST directory match was also detected but cannot be confirmed without direct vendor verification. Overall, Lattice presents as a mature, security-aware SaaS vendor with a well-established domain, clean threat posture, active compliance signaling, and responsible AI data handling commitments. The identified gaps are procedural rather than indicative of material risk.
Independence Statement
All evidence in this report was sourced independently from public registries, threat intelligence databases, DNS/TLS infrastructure scans, and open-source data — without vendor participation or input.