Executive Summary
AI-generated analysis for Lacework
Lacework (lacework.com) is a cloud security vendor assessed at Tier 3 (Moderate Risk) with a 96% confidence score, reflecting a mixed security posture that includes meaningful positive signals alongside notable transparency and configuration gaps. On the positive side, Lacework presents several reassuring indicators:
Key Findings
- The domain has been established for over 23 years, registered since 2002 via enterprise registrar MarkMonitor, with all standard transfer and deletion locks in place.
- Domain reputation is clean across all major threat intelligence blacklists (SURBL, Spamhaus DBL, URLhaus), with zero abuse reports on its primary IP and no malicious indicators detected in website scanning.
- Infrastructure exposure is minimal: only 2 open ports (80, 443) are visible externally with zero known CVEs — a significantly controlled footprint well below the SaaS industry average of 8–12 open ports.
- No sanctions matches, adverse media signals, or historical enforcement actions were identified across OFAC, EU, UN, SEC, or FDIC databases.
- SOC 2 compliance is claimed on a vendor-published support page (vendor-attested, unverified), which is a positive signal pending independent confirmation via the full Type II report. Several concerns warrant attention before or concurrent with onboarding:
- The marketing website (lacework.com) received a failing grade (F, 10/100) from HTTP security scanner, indicating missing HTTP security headers including CSP, HSTS, and X-Frame-Options. While this covers the public site rather than the product application endpoint, it represents a configuration discipline concern.
- No publicly accessible trust center, subprocessor list, or AI data usage policy was found. For a vendor operating in the cloud security space handling medium data access levels, the absence of these standard transparency artifacts is a notable gap relative to peer vendors.
- The domain IP resolves through Fortinet infrastructure (forticloud.com hostname detected), which is relevant context given Fortinet's 2023 acquisition of Lacework — buyers should validate the current corporate and data handling structure.
- No AI data usage policy was publicly discoverable, leaving training commitments, retention practices, and third-party model provider relationships unaddressed for buyers with AI governance requirements. Overall, Lacework presents a clean threat and sanctions profile with a well-controlled infrastructure footprint, but transparency gaps in subprocessor disclosure, trust documentation, and AI policy require direct vendor engagement before full approval.
Independence Statement
All evidence in this report was independently sourced from external data sources without vendor participation or notification.