Privacy Policy & Compliance Architecture

Last updated: July 2, 2026 • Security, Compliance & Regulatory Disclosure

🔑 1. Zero-Knowledge Cryptographic Model

Lattice Vault is built from the ground up on a **Zero-Knowledge Cryptographic Architecture**. Your passwords, custom security questions, web credentials, and secure notes are encrypted and decrypted exclusively within your client browser using AES-256-GCM authenticated encryption with keys derived via PBKDF2.

Critical Guarantee
Your Master Password is processed entirely locally and is never sent to our servers. We do not possess master keys or escrow backdoors. We cannot read, recover, or disclose your vault contents under any circumstances.

📊 2. Data Classification & Handling Matrix

To operate a reliable cloud SaaS platform, we collect minimal operational and billing metadata while enforcing zero-knowledge boundary isolation for all vault items:

Data Category Specific Data Items Security Level Purpose
Vault Items Account Titles, URLs/App targets, Usernames, Passwords, Split Security Questions (Q1–Q5), Notes Client-Side Encrypted (AES-GCM) Zero-Knowledge storage; readable only by you in your browser.
Account Credentials User Master Password One-Way Hashed (Argon2 / PBKDF2) Authentication verification only; raw password is never stored.
Account Metadata Email address, Backup email, Phone number, User role (`owner`/`admin`/`member`), Encryption Salt Server Metadata Account management, login routing, self-recovery authorization.
Workspace & Billing Workspace Name, Plan Tier (`individual`, `family`, `business`), Billing Address, Card Brand & Last 4 Digits Server Metadata Subscription management, quota enforcement, and PCI-DSS compliant billing.
Support Enquiries Submitted Name, Email address, Message Subject, Inquiry Details Server Metadata Customer support responses & private feedback processing.

⚖️ 3. Regulatory Compliance (GDPR & CCPA/CPRA)

Lattice Vault complies strictly with European Union GDPR data protection laws and California CCPA/CPRA consumer privacy frameworks:

💳 4. Payment Card Industry (PCI-DSS) Compliance

Lattice Vault complies with PCI-DSS standards. Full 16-digit credit card numbers, CVV security codes, and PINs are never processed or stored on our servers.

Subscription payments are processed via PCI-certified payment processors (such as Stripe). Payment card details are submitted directly from your browser to the payment gateway over TLS/HTTPS. Our server receives only a secure token, the card brand, and the last 4 digits for billing display.

📬 5. Contacting Privacy & Compliance

If you have questions regarding our Zero-Knowledge security architecture, GDPR compliance, or data deletion policies, you can reach out directly via our private message desk at Lattice Vault Support Desk.