LatticeFlow AI

Security for AI Governance Risk ComplianceApplication Security also known as LatticeFlow AG, LatticeFlow

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2020
Funding $14.8M
Last updated 2026-07-15

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

LatticeFlow AI inventories an enterprise's AI systems, runs technical evaluations and red-team scans, and turns the results into audit-ready EU AI Act evidence. It spun out of ETH Zurich in 2020 to debug computer-vision models and repositioned around AI governance. Its edge is academic credibility a rival cannot quickly assemble. The founders are ETH Zurich professors and researchers, and the team co-authored COMPL-AI, an early technical translation of the EU AI Act covered by TechCrunch. Its named customers, the banking AI maker Unique and the Swiss utility Axpo, are European, with the banking and hiring engagements regulation-driven, and a March 2026 SAP partnership put the platform on the SAP Store. Most defensible for EU-regulated buyers, the open test being adoption outside that pull.

Sourced Details

Description LatticeFlow AI is a Swiss AI governance company whose platform discovers an organization's AI systems, runs technical evaluations and automated red-team security scans, and maps the evidence to 20+ compliance frameworks. [f1]
Founded 2020 [f2]
HQ Zurich, Switzerland [f3]
Funding $14.8M total [f4]
Latest funding Series A ($12M, October 2022) [f3]

Products

Product What it does
LatticeFlow AI Platform AI governance platform that discovers AI systems, runs 100+ ready-to-run evaluations and automated red-team security scans, and generates audit-ready evidence mapped to 20+ governance frameworks.
AI Atlas Free public registry that maps AI frameworks, standards, and regulations to ready-to-run evaluations, giving teams a shared reference for selecting and running framework-aligned assessments.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

The LatticeFlow AI Platform discovers AI models and agentic systems, runs evaluations and automated red-team scans mapped to the EU AI Act, NIST, OWASP, and MITRE, and continuously monitors risk to produce audit-ready governance evidence. These capabilities are mapped to the AI Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 4/5 LatticeFlow names the asset, an enterprise's deployed AI models and agents, and the failures it surfaces, hallucination, bias, data leakage, and security vulnerabilities, then ties them to a compliance gap buyers feel. Independent TechCrunch coverage frames AI risk management and EU AI Act compliance as a real problem, and named regulated customers in banking and energy corroborate the pain beyond vendor marketing, holding the score at strong. [s13, s7, s8]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The platform page details four functions with 20+ frameworks and 100+ evaluations mapped to OWASP and MITRE, but COMPL-AI is a founders' research paper that supports the team rather than validating the product, and no third-party benchmark of the platform itself appears, leaving capability at concrete vendor detail. [s2, s13, s14]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 The EU AI Act and rising enterprise agent adoption since 2023 created the governance-evidence demand LatticeFlow sells into, and regulated buyers in Swiss banking and energy show the pull is funded rather than argued. Independent TechCrunch coverage of the EU AI Act compliance push and a mention in the inaugural 2026 Gartner Magic Quadrant for AI governance platforms mark the category emerging on the buyer side, supporting strong but not exceptional. [s13, s6, s7]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 The four co-founders are ETH Zurich researchers, including CEO Petar Tsankov, CTO Pavol Bielik, and professors Martin Vechev and Andreas Krause, and the team co-authored COMPL-AI, an early technical EU AI Act framework for generative AI published as an arXiv preprint and covered by TechCrunch. That is a verifiable, sustained in-domain research record rather than a single covered event. [s4, s13, s14]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 LatticeFlow shows named, role-attributed customers, the banking AI provider Unique AI on a FINMA-aligned blueprint, the Swiss utility Axpo, and PastaHR validating against the EU AI Act, plus a March 2026 SAP partnership and an SAP Store listing. These are stronger than an anonymous reference bar but remain vendor-displayed rather than independently reported, holding the score at adequate rather than strong. [s5, s7, s8]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 LatticeFlow has raised about $14.8 million since 2020 and runs a small team, yet the visible output, a full governance platform, the AI Atlas registry, COMPL-AI, and an SAP integration, shows reasonable shipping for the raise. A pivot from the original computer-vision product consumed some of that spend, so output per dollar reads adequate rather than clearly efficient. [s10, s9, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 AI governance platforms is now a category buyers and analysts place without vendor coaching, validated by Gartner publishing an inaugural Magic Quadrant for it in 2026, and TechCrunch independently places LatticeFlow in AI risk management and compliance. The score holds at strong rather than exceptional because the Gartner item is a mention read off the vendor's own page rather than an independently distributed quadrant report. [s13, s6, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 GRC platforms, model providers, and the security suites consolidating AI tooling can map evaluations to the same public frameworks LatticeFlow packages, so the framework coverage is reproducible. The ETH research pedigree and COMPL-AI authorship raise brand and replication cost but do not form a structural moat that bundling alone could not overcome. [s9, s5, s2]
Business Risks GRC platform vendors such as OneTrust or Credo AI could map the same public frameworks to evaluations and bundle technical testing into governance suites an enterprise already buys, undercutting a standalone LatticeFlow purchase…
  • GRC platform vendors such as OneTrust or Credo AI could map the same public frameworks to evaluations and bundle technical testing into governance suites an enterprise already buys, undercutting a standalone LatticeFlow purchase.
  • Model providers such as OpenAI and Anthropic could ship native evaluation and red teaming for agents built on their platforms, removing part of the third-party budget line LatticeFlow sells into.
  • Most named customers are European and regulation-driven, so demand may slow if buyers outside Switzerland and the EU do not treat AI governance evidence as a funded priority.
  • Customer evidence rests on vendor-displayed case studies rather than independently reported references, so buyers who demand verifiable production proof could stall deals.
  • The company pivoted from computer-vision data debugging to AI governance, so its earlier enterprise references such as Siemens and Swiss Federal Railways may not carry into the new category.
  • The Gartner recognition is a mention read off the vendor's own page rather than a quadrant placement, so a buyer weighting independent analyst standing may not credit it.
Problem & Market LatticeFlow AI treats an enterprise's deployed AI systems as the asset to govern, and sells software that produces technical evidence those systems are safe enough to run…

LatticeFlow AI treats an enterprise's deployed AI systems as the asset to govern, and sells software that produces technical evidence those systems are safe enough to run. The platform page frames the problem as risks that traditional software testing misses, hallucination, bias, data leakage, and security vulnerabilities, and positions the buyer as the team putting AI into a regulated process and answerable to regulators for it.

The named-customer evidence centers on European, regulation-driven buyers. The company shows a FINMA-aligned banking blueprint built with Unique AI, an engagement with Axpo described as Switzerland's largest renewable energy provider, and PastaHR validating a hiring product against EU AI Act requirements. These accounts establish the pain as a funded compliance concern rather than vendor speculation.

The company has changed what it governs. LatticeFlow launched in 2020 selling tools to find data and model blind spots in computer-vision systems, with early customers including Siemens and the Swiss Federal Railways, and it now centers on governance evidence for generative and agentic AI. The current problem framing fits the EU AI Act era rather than the computer-vision deployment problem it first addressed. [s1, s7, s8]

Product Capabilities The LatticeFlow AI Platform connects four functions that AI governance tools usually split apart…

The LatticeFlow AI Platform connects four functions that AI governance tools usually split apart. The platform page describes discovery of an organization's AI systems, use-case-aware evaluations, automated red-team security scans, and continuous production monitoring, and frames the differentiator as covering pre-launch testing and post-deployment monitoring in one process rather than fragmented tools.

Atlas is the packaged-content layer that makes the evaluations ready to run. The company describes 20+ customizable governance frameworks and 100+ ready-to-run evaluations mapped to standards such as OWASP and MITRE, organized by framework, red-teaming category, or use case, with results translated into risk interpretations, remediation steps, and audit-ready documentation. AI Atlas is also published as a free public registry of frameworks mapped to evaluations.

The research output demonstrates the capability the platform sells. LatticeFlow co-authored COMPL-AI with ETH Zurich and INSAIT, which the company describes as an early framework to translate the EU AI Act into concrete technical requirements for generative AI models. That work is the technical foundation under the platform's framework mappings, and it is harder for a competitor to assemble than the framework coverage alone. [s2, s9, s5]

Competitive Positioning LatticeFlow competes in AI governance against both evaluation specialists and the GRC and security platforms moving into the category…

LatticeFlow competes in AI governance against both evaluation specialists and the GRC and security platforms moving into the category. Giskard sells open-source-seeded LLM evaluation and red teaming, Adversa AI sells continuous adversarial testing, and GRC vendors add policy and documentation workflows. LatticeFlow's distinguishing move is pairing the technical evaluation engine with framework-mapped evidence and a research pedigree from ETH Zurich.

Its visible differentiator is academic authorship and a channel. COMPL-AI gives LatticeFlow a public claim to having translated the EU AI Act into technical requirements, and the March 2026 SAP partnership placed the platform on the SAP Store, a distribution path a smaller rival cannot quickly match. That pairing is the asset LatticeFlow leans on against larger suites.

The structural risk is who owns the framework mapping. The public frameworks LatticeFlow packages, the EU AI Act, NIST, OWASP, and MITRE, are available to any vendor, so a GRC platform or a model provider can map evaluations to the same standards and fold the result into deals an enterprise already signs. The research depth raises replication cost without closing that path. [s5, s9, s11]

Go-to-Market & Traction LatticeFlow's clearest go-to-market proof is a set of named, regulation-driven customer engagements…

LatticeFlow's clearest go-to-market proof is a set of named, regulation-driven customer engagements. The company shows a FINMA-aligned banking blueprint built with Unique AI and quoted by its chief data officer, an engagement with the Swiss utility Axpo, and PastaHR validating a hiring product against EU AI Act requirements. These are vendor-displayed case studies rather than independent press, but they name accounts and roles.

The SAP partnership is the channel signal. In March 2026 LatticeFlow announced a partnership with SAP and listed its platform on the SAP Store, opening a route to enterprises already running SAP and lending the company a large-vendor association its size would not otherwise buy. A marketplace listing is distribution rather than proof of paid volume, but it is a motion beyond direct selling.

Analyst and research visibility rounds out the motion. LatticeFlow promotes a mention in the inaugural 2026 Gartner Magic Quadrant for AI governance platforms and publishes AI Atlas as a free public registry that draws inbound interest. The Gartner item is a mention read off the company's own page rather than a quadrant placement, so it supports awareness more than independent endorsement. [s7, s8, s5, s6]

Team & Credibility LatticeFlow's credibility comes from an ETH Zurich research bench rather than a security-vendor exit…

LatticeFlow's credibility comes from an ETH Zurich research bench rather than a security-vendor exit. The about page identifies the founders as AI professors and researchers from ETH Zurich, naming CEO Petar Tsankov, CTO Pavol Bielik, and professors Martin Vechev and Andreas Krause, the last as scientific advisor. That is a verifiable academic pedigree in machine learning and trustworthy AI.

The research record is the team's strongest public signal. The founders co-authored COMPL-AI, which the company describes as an early EU AI Act framework for generative AI, developed with ETH Zurich and INSAIT, and the company sustains a public output of frameworks and evaluations through AI Atlas. This is an in-domain research pattern rather than a single covered milestone.

The gap relative to the same-asset red-team peers is offensive-security heritage. The founders are academics in AI robustness and safety rather than vulnerability researchers or standards-body security leads, so the team carries deep evaluation science but less of the adversarial-security recognition that some competitors front. The depth is real and sits in AI quality and governance. [s4, s5, s9]

Trust Readiness LatticeFlow states that its SaaS deployment is SOC 2 Type 2 audited, the attestation a security review raises first for a vendor whose product inspects an enterprise's AI systems…

LatticeFlow states that its SaaS deployment is SOC 2 Type 2 audited, the attestation a security review raises first for a vendor whose product inspects an enterprise's AI systems. The platform page reads SOC 2 Type 2 while the AI Defense Matrix Catalog records SOC 2 Type 1, and no inspectable report or trust portal surfaces in the fetched pages, so a procurement team would request the underlying evidence and confirm the report level through a sales conversation.

The deployment model carries part of the trust case. The platform page offers both SaaS and self-hosted deployment, recorded the same way in the catalog, which lets a regulated buyer keep model and evaluation data inside its own environment. That is a material control for a tool that must access proprietary AI systems to test them.

Beyond the attestation, the trust argument leans on transparency and research. The free AI Atlas registry and the public COMPL-AI framework let a buyer inspect the methodology a paid engagement would apply, which addresses part of the question a security review raises when a vendor's product probes proprietary AI. A buyer should still resolve data-handling and retention terms in a formal review. [s15, s16, s9]

Competitors Giskard, Adversa AI, Mindgard, TrojAI, OpenAI…
Company Relationship Note Compare
Giskard competes with Open-source-seeded LLM evaluation and red-teaming specialist contesting the same technical-testing slice of AI governance.
Adversa AI competes with Independent continuous AI red-teaming vendor overlapping LatticeFlow's adversarial-scanning capability.
Mindgard competes with Automated AI red-teaming specialist competing for the same model-testing buyer.
TrojAI competes with AI security and governance vendor pairing red teaming with runtime controls across overlapping AI assets.
OpenAI adjacent Model provider that could ship native evaluation and red teaming for agents built on its platform, removing part of the third-party budget. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with LatticeFlow AI.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

LatticeFlow AI is durable where evaluation science and EU AI Act expertise are slow to assemble, and reproducible elsewhere. What a rival cannot copy by writing software is the ETH Zurich research bench and the provenance of COMPL-AI, though the framework itself is open. The platform delivers evidence a customer configures and runs, so a buyer can cancel and reabsorb the compliance work it offloaded. The framework coverage maps public standards any vendor can read, and the AI Atlas registry and COMPL-AI are published openly rather than held as a non-public corpus. The harder-to-match assets are the ETH pedigree and the early SAP channel, a head start rather than a lasting lead, so compliance platforms and model providers that map to the same rules are the pressure to watch.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy a platform they configure and run that produces evaluations, risk interpretations, and audit-ready documentation, which is software output rather than a managed service that accepts accountability.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Wiring continuous evaluations and audit evidence into a governance workflow builds real friction, but the output is advisory documentation rather than an embedded production control, so a buyer can cancel and reabsorb the compliance work.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 LatticeFlow states its SaaS deployment is SOC 2 Type 2 audited and helps buyers meet the EU AI Act, but the cited record identifies no regulation mandating its platform and the framework coverage maps public standards any vendor can read, so the certification eases procurement without locking a buyer in.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Translating the EU AI Act into executable evaluations is genuinely hard evaluation-ML work, evidenced by the COMPL-AI framework and arXiv preprint, and the vendor describes generated use-case evaluators and agentic red-teaming built on top.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The buyer is the regulated enterprise team accountable for AI, and the named banking, energy, and hiring customers are stronger than an anonymous bar, but they are vendor-displayed with no independently reported production account.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 LatticeFlow discovers, evaluates, and monitors AI systems as an overlay beside the stack rather than infrastructure the model traffic must pass through.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 COMPL-AI and the AI Atlas registry are published openly and the evaluation library maps public frameworks, so the core IP is replicable research and aggregation rather than a named non-public corpus a funded rival could not rebuild.
Strategic Market Segmentation LatticeFlow AI aims at the enterprise team accountable for an AI system in a regulated process, not the developer prototyping a model…

LatticeFlow AI aims at the enterprise team accountable for an AI system in a regulated process, not the developer prototyping a model. The platform frames the buyer as the organization that must prove to regulators and stakeholders that its AI behaves safely, and its named engagements sit in banking through Unique AI, energy through Axpo, and regulated hiring through PastaHR. That is a governance-and-compliance buyer rather than a pure machine-learning team.

The segment is defined by regulatory exposure more than by industry. Two of the customers LatticeFlow shows face concrete rules, the EU AI Act for PastaHR and FINMA expectations for the Unique banking blueprint, while the Axpo engagement is described as finding hidden model blind spots, a quality and reliability concern. That framing fits a Swiss and EU enterprise standing up generative or agentic AI against sensitive data and decisions.

The boundary of the segment is the company's open question. The disclosed customers are European and the banking and hiring engagements are regulation-driven, so the buyer LatticeFlow has best proven is the team facing a near-term compliance deadline. Whether a US enterprise without that deadline buys the same evidence platform is the segment expansion the public record does not yet settle.

Product Capabilities & AI Advantages The LatticeFlow AI Platform connects four functions that governance tools usually split…

The LatticeFlow AI Platform connects four functions that governance tools usually split. The platform page describes discovery of an organization's AI systems, use-case-aware evaluations, automated red-team security scans, and continuous production monitoring, and frames the differentiator as covering pre-launch testing and post-deployment monitoring in one process rather than fragmented tools. The vendor states it generates evaluators tailored to a use case rather than running generic benchmarks.

The framework-mapping engine is the visible AI advantage. LatticeFlow describes 20+ governance frameworks and 100+ ready-to-run evaluations mapped to OWASP and MITRE, packaged through Atlas by framework, red-teaming category, or use case, and translated into risk interpretations, remediation steps, and audit-ready documentation. The mapping of regulatory requirements to executable tests is the company's core technical claim.

COMPL-AI is the research foundation under that claim. LatticeFlow co-authored COMPL-AI with ETH Zurich and INSAIT, an attempt to translate the EU AI Act into concrete technical requirements for generative AI, covered by TechCrunch and published as an arXiv preprint. That work is harder for a competitor to assemble than the framework coverage alone, though the published frameworks LatticeFlow maps to are available to any vendor.

Sales Engagement & Go-to-Market LatticeFlow's clearest go-to-market proof is a set of named, regulation-driven engagements…

LatticeFlow's clearest go-to-market proof is a set of named, regulation-driven engagements. The company shows a FINMA-aligned banking blueprint built with Unique AI and quoted by its chief data officer, an engagement with the Swiss utility Axpo, and PastaHR validating a hiring product against the EU AI Act. These are vendor-displayed case studies rather than independent press, but they name accounts and roles rather than an anonymous reference bar.

The SAP partnership is the channel signal. In March 2026 LatticeFlow announced a partnership with SAP and listed its platform on the SAP Store, opening a route to enterprises already running SAP and lending the company a large-vendor association its size would not otherwise buy. A marketplace listing is distribution rather than proof of paid volume, but it extends the motion beyond direct selling.

Research output is the second engine and it points outward. The COMPL-AI framework drew independent TechCrunch coverage, the AI Atlas registry is published free and public, a choice the company attributes to transparency and shared methodology, and LatticeFlow promotes a mention in the inaugural 2026 Gartner Magic Quadrant for AI governance platforms. The Gartner item is an announcement on the company's own page that states a mention without naming a quadrant position, so it builds awareness more than independent endorsement.

Pricing Model LatticeFlow AI does not publish prices on the fetched pages, routing buyers to a demo request and a talk-to-an-expert flow instead…

LatticeFlow AI does not publish prices on the fetched pages, routing buyers to a demo request and a talk-to-an-expert flow instead. A vendor that hides prices usually targets large negotiated enterprise deals, which fits the regulated banking and energy buyers the company names. The absence withholds the budget-anchoring signal some governance peers publish openly.

The value framing implies the buyer pays for converting regulation into evidence. LatticeFlow positions the platform as replacing manual checklists and static documentation with automated, audit-ready evaluations, so the pitch anchors price to the cost of the manual compliance work it displaces. What the platform charges by, such as AI systems covered, evaluations run, or seats, is not stated publicly.

Confirming the unit and any volume caps would require a sales conversation, which the demo-request flow signals is the intended route. The hidden-price posture is consistent with a company selling negotiated deals into governance, security, and procurement teams rather than a self-serve motion.

Product Delivery & Operations LatticeFlow AI delivers as a continuously operating platform rather than a one-time audit…

LatticeFlow AI delivers as a continuously operating platform rather than a one-time audit. The platform re-evaluates as an application changes and monitors AI systems in production, and the company states its execution engine comes with caching and full traceability. That continuous posture is what turns a periodic compliance review into an ongoing product relationship.

The deployment design answers the data question its own product raises. The platform offers both SaaS and self-hosted deployment, recorded the same way in the AI Defense Matrix Catalog, which lets a regulated buyer keep model and evaluation data inside its own environment. For a tool that must access proprietary AI systems to test them, the self-hosted option is the control a security review checks first.

The operational depth a buyer can verify stays partly private. The fetched pages describe evaluations, red-team scans, remediation steps, and audit-ready documentation, but expose no public status page or service-level commitment. A security review will probe how LatticeFlow handles the model and evaluation data it must inspect, and the public record does not yet fully answer that.

Earning Customers' Trust LatticeFlow AI states that its SaaS deployment is SOC 2 Type 2 audited, the attestation a security review raises first for a vendor whose product inspects an enterprise's AI systems…

LatticeFlow AI states that its SaaS deployment is SOC 2 Type 2 audited, the attestation a security review raises first for a vendor whose product inspects an enterprise's AI systems. The AI Defense Matrix Catalog records a SOC 2 Type 1 attestation, so the public signals disagree on the report level, and no inspectable report or trust portal surfaces in the fetched pages. A procurement team would request the underlying evidence and confirm the report level through a sales conversation.

The attestation is enterprise readiness rather than a moat. SOC 2 eases procurement but locks no buyer in, and the cited record identifies no regulation mandating purchase of an AI governance platform, so the certification is a credibility floor that a funded rival can also clear. The trust case rests more on what LatticeFlow publishes than on the badge.

Transparency carries part of the trust argument. The free AI Atlas registry and the public COMPL-AI framework let a buyer inspect the methodology a paid engagement would apply, which addresses part of the question a security review raises when a vendor's product probes proprietary AI. A buyer should still resolve data-handling and retention terms in a formal review beyond the published badge.

Platform Strategy & Ecosystem Positioning LatticeFlow AI positions itself as a governance layer that sits beside the AI stack an enterprise already runs…

LatticeFlow AI positions itself as a governance layer that sits beside the AI stack an enterprise already runs. It discovers, evaluates, and monitors the models and agents a customer operates without owning any of them, so it is an overlay above the AI systems rather than infrastructure the model traffic must pass through. The public material describes evaluation and monitoring rather than an inline enforcement point that blocks unsafe responses in real time, a position that holds no chokepoint.

The SAP relationship is the ecosystem asset LatticeFlow leans on. The platform is listed on the SAP Store and the partnership targets enterprises running SAP AI workloads, which gives a small company a distribution path a copycat cannot quickly assemble. The published AI Atlas registry and COMPL-AI framework add reach by becoming reference points other teams cite.

What exposes LatticeFlow is who owns the framework mapping and the buyer. The public frameworks it packages, the EU AI Act, NIST, OWASP, and MITRE, are available to any vendor, and GRC platforms or model providers can map evaluations to the same standards and fold the result into deals an enterprise already signs. The research depth raises replication cost without closing that path.

Team & Execution Capability LatticeFlow AI's credibility comes from an ETH Zurich research bench rather than a security-vendor exit…

LatticeFlow AI's credibility comes from an ETH Zurich research bench rather than a security-vendor exit. The about page identifies the founders as AI professors and researchers from ETH Zurich, naming CEO Petar Tsankov, CTO Pavol Bielik, and professors Martin Vechev and Andreas Krause, the last as scientific advisor. That is a verifiable academic pedigree in machine learning, robustness, and trustworthy AI.

The research record is the team's strongest public signal. Three of the founders, Tsankov, Bielik, and Vechev, co-authored COMPL-AI, an attempt to translate the EU AI Act into technical requirements, developed with ETH Zurich and INSAIT, covered by TechCrunch and posted as an arXiv preprint. That is directly in-domain research credibility, anchored by one covered flagship project, and it is the credibility the company trades on with regulated buyers.

The founders' public profile sits in evaluation science rather than offensive security. The cited pages show expertise in formal methods, symbolic reasoning, and machine learning and document no vulnerability-research or standards-body security roles, so the recognition the team fronts is AI quality and governance rather than adversarial-security heritage.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 https://latticeflow.ai/platform official 2026-06-25
f2 TechCrunch: LatticeFlow raises $12M to eliminate computer vision blind spots press 2026-06-25
f3 FinSMEs: LatticeFlow Raises $12M in Series A Funding press 2026-06-25
f4 startupticker.ch: LatticeFlow raises $12M to fix AI data and model errors press 2026-06-25
f5 AI Defense Matrix Catalog: LatticeFlow AI product entry official 2026-06-25
Profile Analysis Sources (16)
Id Source Tier Accessed
s1 LatticeFlow AI platform page: discovery, evaluations, security testing, monitoring
“The LatticeFlow AI Platform enables continuous monitoring and risk interpretation through integrated discovery, evaluations, and security testing.”
official 2026-06-25
s2 LatticeFlow AI platform page: 20+ frameworks, 100+ ready-to-run evaluations
“LatticeFlow AI includes 20+ customizable governance frameworks and 100+ ready-to-run evaluations mapped to standards like OWASP and MITRE.”
official 2026-06-25
s3 TechCrunch: LatticeFlow raises $12M Series A, ETH Zurich spin-out 2020
“LatticeFlow, a startup that was spun out of Zurich's ETH in 2020 ... the company currently has more than 10 customers ... including a number of large enterprises like Siemens and organizations like the Swiss Federal Railways.”
press 2026-06-25
s4 LatticeFlow AI about page: ETH Zurich founders and leadership
“We are leading AI professors and researchers from ETH Zurich ... Dr. Petar Tsankov Co-founder and CEO. Dr. Pavol Bielik Co-founder and CTO. Prof. Dr. Martin Vechev Co-founder. Prof. Dr. Andreas Krause Co-founder and Scientific Advisor.”
official 2026-06-25
s5 LatticeFlow AI news: SAP partnership, platform on SAP Store
“LatticeFlow AI ... today announced a partnership with SAP ... businesses that use SAP solutions can gain access to LatticeFlow AI platform which is now available on SAP Store. As the creator of COMPL-AI, the world's first EU AI Act framework for Generative AI developed with ETH Zurich and INSAIT.”
official 2026-06-25
s6 LatticeFlow AI news: mention in inaugural Gartner Magic Quadrant for AI Governance Platforms
“LatticeFlow AI, a Swiss deep-tech company specializing in AI trust, risk, and security management, today announced its mention in the inaugural 2026 Gartner Magic Quadrant for AI Governance Platforms.”
official 2026-06-25
s7 LatticeFlow AI customer story: Unique AI FINMA-aligned banking blueprint
“The blueprint we developed with LatticeFlow AI reflects our commitment to building AI that meets the expectations of Switzerland's highly regulated financial sector. - Dr. Sina Wulfmeyer Chief Data Officer at Unique AI.”
official 2026-06-25
s8 LatticeFlow AI customer stories: PastaHR, Axpo, Unique
“PastaHR partnered with LatticeFlow AI to validate JobFit against EU AI Act requirements ... LatticeFlow AI partnered with Axpo, Switzerland's largest renewable energy provider, to assess and mitigate AI risk by detecting hidden model blind spots.”
official 2026-06-25
s9 LatticeFlow AI news: AI Atlas public registry launch
“AI Atlas ... a public registry of AI governance frameworks mapped to ready-to-run technical evaluations ... builds on LatticeFlow AI's work in AI risk control and COMPL-AI, the first framework to translate the EU AI Act into concrete technical requirements for generative AI models.”
official 2026-06-25
s10 startupticker.ch: LatticeFlow Series A brings total funding to $14.8M
“The ETH Zurich spin-off, founded in 2020 ... announced a $12 million Series A funding round ... The new investment brings LatticeFlow's total funding to $14.8 million.”
press 2026-06-25
s11 Adversa AI homepage: continuous red teaming for custom AI agents
“Adversa AI delivers continuous red teaming and remediation for the custom AI agents your business runs on.”
official 2026-06-25
s12 Giskard homepage: open-source AI evaluation and red-teaming
“Giskard ... testing of AI models for hallucination, prompt injection, and security flaws.”
official 2026-06-25
s13 TechCrunch: LatticeFlow COMPL-AI benchmarks Big AI compliance with the EU AI Act
“LatticeFlow AI, a spinout from public research university ETH Zurich, which is focused on AI risk management and compliance ... published what it's touting as the first technical interpretation of the EU AI Act ... a long-term collaboration between ETH Zurich and Bulgaria's INSAIT.”
press 2026-06-25
s14 arXiv preprint: COMPL-AI Framework, a technical interpretation and LLM benchmarking suite for the EU AI Act
“COMPL-AI Framework: A Technical Interpretation and LLM Benchmarking Suite for the EU Artificial Intelligence Act.”
research 2026-06-25
s15 LatticeFlow AI platform page: SaaS and self-hosted deployment, SOC 2 Type 2 audited
“Deploy Your Way ... SaaS ... SOC 2 Type 2 audited, your data stays private ... Self-Hosted.”
official 2026-06-25
s16 AI Defense Matrix Catalog: LatticeFlow AI deployment and attestations
“Deployment: SaaS, Self-hosted. Compliance attestations: SOC 2 Type 1.”
official 2026-06-25
Deep-Dive Sources (14)
Id Source Tier Accessed
s1 LatticeFlow AI platform page: discovery, evaluations, security testing, monitoring
“The LatticeFlow AI Platform enables continuous monitoring and risk interpretation through integrated discovery, evaluations, and security testing.”
official 2026-06-25
s2 LatticeFlow AI platform page: 20+ frameworks, 100+ ready-to-run evaluations, deployment
“LatticeFlow AI includes 20+ customizable governance frameworks and 100+ ready-to-run evaluations mapped to standards like OWASP and MITRE ... Audit-ready evidence mapped to 20+ frameworks (EU AI Act, NIST, ISO,...) ... SaaS ... SOC 2 Type 2 audited, your data stays private.”
official 2026-06-25
s3 LatticeFlow AI platform page: how it differs, generated evaluators, remediation
“LatticeFlow AI ... combining app-specific evaluations and adversarial testing before launch with continuous production monitoring afterward ... it generates evaluators tailored to your use case and translates results into clear risk interpretations, remediation steps, and audit-ready documentation.”
official 2026-06-25
s4 LatticeFlow AI about page: ETH Zurich founders and leadership
“We are leading AI professors and researchers from ETH Zurich ... Dr. Petar Tsankov Co-founder and CEO. Dr. Pavol Bielik Co-founder and CTO. Prof. Dr. Martin Vechev Co-founder. Prof. Dr. Andreas Krause Co-founder and Scientific Advisor.”
official 2026-06-25
s5 LatticeFlow AI news: SAP partnership, platform on SAP Store, COMPL-AI creator
“businesses that use SAP solutions can gain access to LatticeFlow AI platform which is now available on SAP Store. As the creator of COMPL-AI, the world's first EU AI Act framework for Generative AI developed with ETH Zurich and INSAIT, the company combines Swiss precision with scientific rigor.”
official 2026-06-25
s6 LatticeFlow AI news: mention in inaugural Gartner Magic Quadrant for AI Governance Platforms
“LatticeFlow AI, a Swiss deep-tech company specializing in AI trust, risk, and security management, today announced its mention in the inaugural 2026 Gartner Magic Quadrant for AI Governance Platforms.”
official 2026-06-25
s7 LatticeFlow AI customer story: Unique AI FINMA-aligned banking blueprint
“The blueprint we developed with LatticeFlow AI reflects our commitment to building AI that meets the expectations of Switzerland's highly regulated financial sector. - Dr. Sina Wulfmeyer Chief Data Officer at Unique AI.”
official 2026-06-25
s8 LatticeFlow AI customer stories: PastaHR, Axpo, Unique
“PastaHR partnered with LatticeFlow AI to validate JobFit against EU AI Act requirements ... LatticeFlow AI partnered with Axpo, Switzerland's largest renewable energy provider, to assess and mitigate AI risk by detecting hidden model blind spots.”
official 2026-06-25
s9 LatticeFlow AI news: AI Atlas public registry launch
“AI Atlas ... a public registry of AI governance frameworks mapped to ready-to-run technical evaluations ... builds on LatticeFlow AI's work in AI risk control and COMPL-AI, the first framework to translate the EU AI Act into concrete technical requirements for generative AI models.”
official 2026-06-25
s10 TechCrunch: LatticeFlow COMPL-AI benchmarks Big AI compliance with the EU AI Act
“LatticeFlow AI, a spinout from public research university ETH Zurich, which is focused on AI risk management and compliance ... published what it's touting as the first technical interpretation of the EU AI Act ... a long-term collaboration between ETH Zurich and Bulgaria's INSAIT.”
press 2026-06-25
s11 arXiv preprint: COMPL-AI Framework, a technical interpretation and LLM benchmarking suite for the EU AI Act
“COMPL-AI Framework: A Technical Interpretation and LLM Benchmarking Suite for the EU Artificial Intelligence Act.”
research 2026-06-25
s12 startupticker.ch: LatticeFlow Series A brings total funding to $14.8M, founded 2020
“The ETH Zurich spin-off, founded in 2020 ... announced a $12 million Series A funding round ... The new investment brings LatticeFlow's total funding to $14.8 million.”
press 2026-06-25
s13 AI Defense Matrix Catalog: LatticeFlow AI deployment and attestations
“Deployment: SaaS, Self-hosted. Compliance attestations: SOC 2 Type 1. Discovers AI assets, runs 100+ evaluations mapped to 20+ frameworks such as the EU AI Act and NIST, scans for vulnerabilities via automated red-teaming aligned with OWASP and MITRE.”
official 2026-06-25
s14 Adversa AI homepage: continuous red teaming for custom AI agents
“Adversa AI delivers continuous red teaming and remediation for the custom AI agents your business runs on.”
official 2026-06-25

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.