Lattice

United States · lattice.com · 27 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 27 sub-vendors.

Insights

Last updated 2026-08-16 · revision 2

27 direct vendors, 283 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Lattice exhibits a strong foundation for migration readiness, primarily due to its highly modern and cloud-native technical architecture. The company's reliance on Amazon Web Services (AWS) and Google Cloud demonstrates a multi-cloud strategy, significantly reducing vendor lock-in to a single cloud provider and providing flexibility for future migrations or re-platforming efforts. The tech stack is characterized by advanced technologies like AI, LLMs, and an API-driven approach (REST API / Webhooks), which are inherently designed for interoperability and portability. The 'Lattice MCP (Model Context Protocol)' further suggests an architectural design that facilitates integration and potentially eases the transition of data and workflows between different systems. Existing compliance with SOC 2 and GDPR frameworks means that the necessary governance and security controls are already in place, which, while requiring careful consideration during migration, provides a structured approach to maintaining regulatory adherence. However, several factors introduce uncertainty and potential challenges for migration. A critical unknown is the absence of specified data residency requirements. If strict data residency rules apply, migrating data across different geographic regions or cloud providers could become significantly more complex and costly. Furthermore, the lack of financial stability data (revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a potentially expensive and resource-intensive migration project. While the multi-cloud strategy mitigates cloud provider lock-in, the company utilizes a significant number of internal tech stack components and offers 28 services, implying numerous integrations (e.g., HRIS, Slack, Teams). Migrating or re-integrating these diverse services could present considerable complexity and effort. The explicit 'Vendor Lock-in Risk' is also unknown, which could impact the ease of transitioning away from certain tools or platforms.

Compliance

5 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

No ISO 27001 certification is explicitly mentioned in Lattice's publicly available Trust Center or Privacy Policy. Lattice's Trust Center lists SOC 2, GDPR, and CCPA compliance but does not reference ISO 27001 certification. However, Lattice does maintain a comprehensive information security program with controls that align with ISO 27001 principles (access control, asset management, incident response, BC/DR, penetration testing, etc.). The absence of ISO 27001 certification is notable for an enterprise HR SaaS platform serving global customers, as many enterprise procurement teams require it. Risk is Medium because: (1) the absence of ISO 27001 may create friction in enterprise sales cycles, particularly with EU/UK customers who commonly require it; (2) Lattice's security posture appears strong based on SOC 2 and other controls, suggesting the underlying security program may be certifiable; (3) without certification, there is no independent third-party validation of the ISMS against ISO 27001 standards.

Evidence: https://trustcenter.lattice.com/

EU AI Act (source) — Assessment Required

The EU AI Act (Regulation 2024/1689) entered into force in August 2024 with phased implementation through 2027. Lattice has significantly expanded its AI capabilities, including an 'AI Agent' for HR, AI-powered engagement insights, evidence-based review drafts, and AI analytics. HR AI systems — particularly those used for employee performance evaluation, talent reviews, succession planning, and compensation decisions — may qualify as 'high-risk AI systems' under Annex III of the EU AI Act (specifically Article 6 and Annex III, point 4: 'AI systems intended to be used for recruitment or selection of natural persons, notably for advertising vacancies, screening or filtering applications, evaluating candidates in the course of interviews or tests' and point 4(b): 'AI systems intended to be used for making decisions on promotion and termination of work-related contractual relationships, for task allocation and for monitoring and evaluating performance and behavior of persons in such relationships'). Risk is Medium because: (1) Lattice's AI features directly touch employment decisions; (2) EU AI Act high-risk classification would impose significant obligations (conformity assessments, technical documentation, human oversight requirements, transparency obligations); (3) Lattice serves EU-based customers whose employees are EU residents; (4) Enforcement begins for high-risk systems in August 2026.

Evidence: https://lattice.com/ai, https://lattice.com/trust/lattice-artificial-intelligence-use-terms-and-consent-for-data-processing, https://trustcenter.lattice.com/

GDPR (source) — Compliant

Lattice explicitly acknowledges GDPR applicability and has implemented multiple compliance mechanisms: a named Data Protection Officer (dpo@lattice.com), an EU Representative (Osano International Compliance Services Limited, Dublin, Ireland), Standard Contractual Clauses for international data transfers, a Data Processing Addendum, data subject rights procedures, and a Schrems II compliance page. As a US-headquartered HR SaaS platform serving 5,000+ global customers — including EU/EEA-based organizations such as GoCardless (UK/EU) — Lattice processes significant volumes of EU employee personal data. Risk is Medium rather than Low because: (1) Lattice acts as both a data controller (for visitor/marketing data) and a data processor (for customer HR data), creating dual compliance obligations; (2) HR data is among the most sensitive categories under GDPR; (3) enforcement of GDPR against US-based SaaS processors has intensified (e.g., Schrems II implications, EU-US Data Privacy Framework scrutiny); and (4) AI features processing employee data introduce additional GDPR Article 22 (automated decision-making) considerations. Compliance posture appears strong based on public disclosures.

Evidence: https://trustcenter.lattice.com/, https://lattice.com/trust/privacy-policy, https://lattice.com/trust/data-processing-addendum, https://lattice.com/trust/subprocessors, https://lattice.com/trust/schrems-ii, https://preferences.lattice.com/privacy

Financials

Three-year financials

Financial Resilience Score: 6/10

Lattice is a well-funded, category-leading private HR-tech SaaS company with strong recurring revenue characteristics and a diversified customer base of 5,000+ logos. It has raised approximately $328M in cumulative equity funding through Series F (July 2022) at a $3B valuation, backed by tier-1 investors including Tiger Global, Dragoneer, Thrive Capital, Founders Fund, and Khosla Ventures, providing meaningful capital reserves. Revenue trajectory has been strongly positive, growing from low-double-digit-million ARR in 2020 to over $100M ARR by 2023. However, as a late-stage private SaaS company that grew headcount aggressively and then executed multiple layoffs in 2023, Lattice has almost certainly been unprofitable at the operating level, with no public runway or profitability data. The $3B valuation was set during the 2021-2022 zero-interest-rate SaaS bubble and faces reset risk. Competitive intensity is significant, with pressure from Workday, SAP SuccessFactors, Rippling, HiBob, BambooHR, Culture Amp, 15Five, and Leapsome. Post-2023 emphasis on operating discipline and a diversified multi-product suite (Performance, Engagement, Goals/OKRs, Grow, Compensation, AI Agent) support resilience, but lack of audited financials limits confidence in the assessment.

Key strengths: ~$328M cumulative equity raised through Series F, 5,000+ customer base with strong logo diversity (Robinhood, Duolingo, Discord, Gusto), Recurring SaaS revenue model with land-and-expand across multiple products, Tier-1 investor backing (Tiger Global, Dragoneer, Thrive, Founders Fund), Category leader on G2 in performance management, Experienced leadership (CEO ex-Salesforce, CFO ex-Conga), ARR grew from low tens of millions in 2020 to >$100M by 2023

Risk factors: Cash burn and profitability unknown; likely operating losses, Valuation reset risk from 2022 $3B peak set in ZIRP era, Intense competitive pressure from Workday, Rippling, HiBob, BambooHR and others, 2023 layoffs (~15% of staff) signal prior over-hiring, 2024 AI-worker HRIS controversy raised reputational/execution concerns, HRIS pivot introduces implementation and integration risk, Historical concentration in tech-sector customers exposes to hiring downturns, No public financial disclosures (private company)

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report