Trust

Security

How The Latent approaches security for our people, systems, and the services we provide to readers.

Last updated: July 23, 2026

Introduction

The Latent’s security policies and practices seek to ensure compliance with all applicable laws, regulations, and our contractual obligations. Our policies and practices also seek to ensure the confidentiality and integrity of our data as well as the availability of the services we provide.

Policies

The Latent’s security policies apply to all employees (full or part time), interns, and contractors. All policies are approved by leadership and are scheduled to be reviewed yearly. We have a variety of policies in place to cover topics such as change management, third party vendors, acceptable use, and risk management.

Authentication and authorization

All user accounts require both complex passwords (minimum of 10 characters) and MFA.

Access to resources is based on the principle of least privilege and is granted through a change management process. Access that is not needed long term is reversed.

Trainings

All new hires receive an initial security training. All employees receive monthly security micro-trainings on rotating topics. Educational phishing simulations are run on a monthly basis. Other trainings are held on a rolling basis.

Environments

Testing and production environments are logically separated. Corporate users have no access to testing or production. Each boundary is protected by a firewall that limits the ports and services to those required. Access to various environments is based on business need.

Change management

All changes to production and sensitive access grants go through a change management process. Separation of duties is enforced during the change management process. All requests are reviewed regardless of approval status. An emergency process for after-hour urgent changes is also in place.

Email security

An email firewall is in place to scan for malware in attachments and block suspicious emails. Email servers will attempt to negotiate encryption if the sender’s server also supports encryption. Email is equipped with a “report phishing” button that allows employees to alert the Security Team to any phishing emails that made it past the firewall.

Vulnerability scanning

Production infrastructure is scanned on a monthly basis. Identified vulnerabilities are addressed based on criticality level.

Encryption

All data of confidential or above is encrypted at rest (AES-256) and in transit (TLS 1.2 or above).

Vendor management

Vendors that store, process, or transmit confidential or above data receive a risk evaluation by the Security Team.

Vendor security posture, terms of service, and privacy practices are evaluated.

Contact

For security questions or responsible vulnerability reports, contact security@thelatent.co.

Privacy Policy · Terms of Service · Contact