Privacy Policy & Compliance Architecture
Last updated: July 2, 2026 • Security, Compliance & Regulatory Disclosure
1. Zero-Knowledge Cryptographic Model
Lattice Vault is built from the ground up on a **Zero-Knowledge Cryptographic Architecture**. Your passwords, custom security questions, web credentials, and secure notes are encrypted and decrypted exclusively within your client browser using AES-256-GCM authenticated encryption with keys derived via PBKDF2.
2. Data Classification & Handling Matrix
To operate a reliable cloud SaaS platform, we collect minimal operational and billing metadata while enforcing zero-knowledge boundary isolation for all vault items:
| Data Category | Specific Data Items | Security Level | Purpose |
|---|---|---|---|
| Vault Items | Account Titles, URLs/App targets, Usernames, Passwords, Split Security Questions (Q1–Q5), Notes | Client-Side Encrypted (AES-GCM) | Zero-Knowledge storage; readable only by you in your browser. |
| Account Credentials | User Master Password | One-Way Hashed (Argon2 / PBKDF2) | Authentication verification only; raw password is never stored. |
| Account Metadata | Email address, Backup email, Phone number, User role (`owner`/`admin`/`member`), Encryption Salt | Server Metadata | Account management, login routing, self-recovery authorization. |
| Workspace & Billing | Workspace Name, Plan Tier (`individual`, `family`, `business`), Billing Address, Card Brand & Last 4 Digits | Server Metadata | Subscription management, quota enforcement, and PCI-DSS compliant billing. |
| Support Enquiries | Submitted Name, Email address, Message Subject, Inquiry Details | Server Metadata | Customer support responses & private feedback processing. |
3. Regulatory Compliance (GDPR & CCPA/CPRA)
Lattice Vault complies strictly with European Union GDPR data protection laws and California CCPA/CPRA consumer privacy frameworks:
- Right to Erasure ("Right to be Forgotten"): When you delete a workspace, our PostgreSQL database executes cascade deletions (`ON DELETE CASCADE`) to permanently purge all associated user records, billing metadata, and encrypted vault entries.
- Data Minimization: We collect only the minimum metadata necessary to process payments and authenticate workspace users. We never sell, rent, or trade personal metadata to third-party advertisers.
- Data Portability: You can export your entire decrypted vault at any time in standard Excel/CSV formats directly from the Vault App shell.
- Data Encryption at Rest: Operational server databases and backups are protected using encrypted storage volumes (AES-256 at rest).
4. Payment Card Industry (PCI-DSS) Compliance
Lattice Vault complies with PCI-DSS standards. Full 16-digit credit card numbers, CVV security codes, and PINs are never processed or stored on our servers.
Subscription payments are processed via PCI-certified payment processors (such as Stripe). Payment card details are submitted directly from your browser to the payment gateway over TLS/HTTPS. Our server receives only a secure token, the card brand, and the last 4 digits for billing display.
5. Contacting Privacy & Compliance
If you have questions regarding our Zero-Knowledge security architecture, GDPR compliance, or data deletion policies, you can reach out directly via our private message desk at Lattice Vault Support Desk.