Executive Summary
AI-generated analysis for Lattice
Lattice (lattice.com) is an HR and people management SaaS platform serving 5,000+ organizations, assessed at Tier 4 (Low Risk) with a confidence score of 78%. The platform operates at a medium data access level, handling sensitive employee and performance data. Several positive signals support the low-risk determination:
Key Findings
- The domain is nearly 30 years old and registered through 2028, indicating a well-established digital presence.
- Domain infrastructure is healthy, with TLS 1.3 encryption, a strong AES-256-GCM cipher suite, and all key security headers (HSTS, CSP, X-Frame-Options) in place.
- Lattice's HTTP security headers scored a B (70/100) from HTTP security scanner — a solid baseline.
- Malware detection service and sanctions screening returned clean results, with no adverse media identified in current or historical scans.
- All infrastructure is routed through Cloudflare, providing DDoS protection and CDN-layer security.
- Lattice explicitly commits to not training AI models on customer data, a meaningful privacy assurance for organizations deploying its AI-assisted performance management features. Third-party AI providers OpenAI and Anthropic are disclosed, sourced from the vendor's security page.
- SOC 2 compliance is claimed on the vendor's trust page (https://lattice.com/security), supported by a Drata trust management platform presence, indicating an active compliance posture. Three areas warrant attention before or during onboarding:
- Lattice's infrastructure presents 13 open ports, which — while all consistent with Cloudflare CDN infrastructure — represents an above-average external footprint compared to the SaaS industry norm of 8–12 ports. Buyers should confirm all services require public exposure.
- SOC 2, GDPR, and CCPA are vendor-attested (not independently verified through a public registry). The SOC 2 claim is strengthened by the Drata platform association, but compliance teams should request the full Type II report and a current bridge letter.
- The vendor's subprocessor page (https://lattice.com/subprocessors) was found but could not be automatically parsed, leaving supply chain visibility incomplete. Manual review is recommended, particularly given GDPR Article 28 obligations. Overall, Lattice presents a well-controlled risk profile consistent with a mature SaaS vendor. Outstanding items are manageable through standard pre-contract due diligence and do not represent material barriers to procurement.
Independence Statement
All evidence cited in this report was independently sourced from external data providers and public registries without vendor participation or input.