Skip to content

Security: latticeHQ/latticeWorkbench

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x Yes
< 1.0 No

Reporting a Vulnerability

If you discover a security vulnerability in Lattice, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, email security@latticeruntime.com with:

  1. A description of the vulnerability
  2. Steps to reproduce
  3. Potential impact
  4. Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 5 business days
  • Fix or mitigation: depends on severity, targeting 30 days for critical issues

Scope

The following are in scope:

  • Lattice desktop application (Electron)
  • Built-in MCP server
  • Agent orchestration and sandboxing
  • SSH remote runtime connections
  • Auto-updater and code signing

Out of scope:

  • Third-party AI provider APIs (report to the provider directly)
  • Self-hosted infrastructure not maintained by Lattice

Disclosure

We follow coordinated disclosure. We will credit reporters in the release notes unless anonymity is requested.

There aren’t any published security advisories