Domain Systems

Lattice

Full cross-domain solution software. Orchestrate file transfers, configure ENS pipelines, enforce human review policies, and operate your data diode deployment from a unified web console, built for air-gapped and critical infrastructure networks.

System overview

Activity across tickets, file transfer, connections, and host resources.

Updated 11:00

Data volume (file transfer, last 24h)

Transfer events by interval (last 24h)

Tickets by status

Connection rules

12 rules · 12 enabled · 11 running

  • Running11
  • Stopped1
Role
Sender · 9Receiver · 3
Transport
Tcp · 12

Pipelines & tools

46 pipeline stages across 12 rules — tool stages below.

tcp-server×11buffer×9pitcher×9rate-limiter×9reorderer×3tcp-client×3catcher×1stdin×1
RuleStatusRole / transportStagesTraffic
SCADA Modbus receiver (UDP)485374d7-00a6-41c0-b328-6911ad58cd5erunningreceiver · tcplisten 9000 → target 5023148.8 MB/s
391.2 GB session
Substation DNP3 senderd0c02dcf-438c-4788-a086-2ac8430ee2a2runningsender · tcplisten 20000 → target 91004171.7 MB/s
479.6 GB session
Plant syslog forwarder46a11cae-9de1-40fa-99cc-c64656ecca7frunningsender · tcplisten 1514 → target 95144194.5 MB/s
568.1 GB session
Tactical BFT position feedc9c64178-50df-4bf5-8246-83d37a47cbd1runningsender · tcplisten 8087 → target 98075217.4 MB/s
656.6 GB session
ISR metadata exportd4365548-5d42-410c-8b48-a14460266c72runningsender · tcplisten 5004 → target 95044240.3 MB/s
745.1 GB session
Netflow export6ef361da-3fb7-49d5-b698-ea8142f16449runningsender · tcplisten 2055 → target 92054263.2 MB/s
833.5 GB session

Key metrics

Tickets

9
12 new in last 24h

File transfers

47
Completed in range

Files

128
Across diode

Data (file transfer)

2.43 TB
Sent in range

Connection rules

12
11 running · 12 enabled

Pipeline throughput

1.21 GB/s
Running pipelines (tap)

Diode bytes (pipelines)

3.59 TB
Session total (running)

Download events

23
User pulls in range

Files downloaded

18
Distinct files with activity

Memory

31%
5.0 GB / 16.0 GB

Disk (/var/lib/lattice)

42%
5.0 TB / 12.0 TB

Load (1m)

0.42
CPU pressure hint

Activity log

  • 10:12:00FTFile transfer NORTHPIER-ZONE-848 completed (3 files)
  • 10:10:00ConnConnection rule "SCADA Modbus receiver (UDP)" started
  • 10:07:00FTFile transfer CANYON-SEG-845 completed with errors (2 of 3 files)
  • 09:55:00ConnConnection rule "Substation DNP3 sender" started
File transfer volume, tickets, connection rules, and live activity.Use the view menu to explore the console

The operations console for every cross-domain scenario

Hardware diodes enforce one-way flow at the physical layer. Lattice is the operations layer — transfers, pipelines, review, and audit — from one console in your protected enclave.

The platform is the same everywhere. Which capabilities matter most depends on your sector — mapped on the right.

Everything you need to operate a CDS

File transfer, protocol bridging, inspection, human review, identity, and administration — from one platform.

System Overview

Real-time KPIs for file transfer volume, connection throughput, ticket status, host resources, and an activity feed — configurable from 1 to 168 hours, on either side of the boundary.

Connection Orchestration

Visual ENS pipeline rules for Modbus TCP, raw UDP/TCP, and custom multi-stage flows — with live traffic sparklines, import/export, and per-rule start/stop.

Ticket-Based File Transfer

Multi-file uploads with SHA-256 hashing, chunked transfer, recipient addressing, and RSA-4096 signed JWTs that authorize every cross-domain movement with bilateral revocation tracking.

Ticket Provenance

Per-file timelines from upload through inspection, diode transit, antivirus, human review, and pickup — with hashes, disposition codes, and cross-domain audit context.

Reliable Human Review

Policy-driven review queues with assignment, attestation, duplicate detection, rich comments, notifications, and optional download-before-approve enforcement.

Admin & Audit

24-permission RBAC with custom roles, user approval workflows, runtime system settings, and a tamper-evident audit chain with verification endpoint.

Content Inspection

Defense-in-depth pipeline: magic-byte detection, MIME/extension policy, Google Magika ML typing, dirty-word filtering, and configurable AV scanning — with block, warn, or quarantine per stage.

mTLS Non-Repudiation

Bind uploads and downloads to client certificates (CAC, YubiKey, or software certs). Identity is recorded on every transfer and carried across the diode in the manifest.

Identity & Access

Local accounts or LDAP/AD, email verification, session management, password policy, personal access tokens, and registration approval before first login.

Defense in depth at every layer

Cryptographic authorization, content inspection, antivirus, non-repudiation, and auditable operations — enforced server-side in your protected enclave.

Cryptographic gatekeeping

Every file transfer requires cryptographic authorization before data crosses your boundary. Revocation is tracked so pulled approvals are honored throughout the deployment.

Multi-stage content inspection

Files are analyzed with libmagic, MIME/extension consistency checks, Google Magika ML classification with configurable certainty thresholds, and optional dirty-word filtering — on the air-gapped side before AV, and optionally at upload on the external network.

Air-gapped AV updates

AV definition updates can be delivered into the protected network as approved system tickets — no outbound internet required on the air-gapped side.

Tamper-evident audit

Admin actions are recorded in a hash-chained audit log with optional HMAC signing. Operators can verify chain integrity via the API. Per-user audit history is available in Profile.

Client certificate binding

Optional mandatory mTLS for uploads and data access binds every transfer to a cryptographic identity. Certificate enrollment, multi-binding limits, and fingerprint-based identification via nginx integrate with CAC, YubiKey, and software certificates.

Quarantine & recovery

Failed inspection, policy violations, and malware are quarantined with reason codes — infected, policy_mime, policy_words, policy_magika_certainty, and more. Admins can release individual files or bulk-quarantine on the air-gapped side when investigation warrants it.

See Lattice in action

A walkthrough of the core views operators use every day.

Lattice system overview dashboard showing file transfer metrics and connection rules

Single-pane visibility into your node

The system overview shows file transfer volume, transfer events, tickets by status, and connection rule health at a glance. Drill into pipeline stages (ens-catcher, ens-pitcher, ens-reorderer, and more) and see live traffic per rule.

Lattice Add connection rule dialog with TCP sender preset and custom ENS pipeline stages

Configure ENS pipelines visually

Define sender and receiver rules for Modbus TCP, raw UDP/TCP, syslog, and custom protocols. Compose multi-stage pipelines with catchers, buffers, rate limiters, and tee branches — then enable, disable, and monitor each rule with live traffic sparklines.

Lattice file transfer dashboard showing completed tickets

Every transfer tracked by ticket

Browse completed and in-progress tickets across your deployment. Search by file name, SHA256 hash, ticket ID, or date. Upload from the console or drive transfers programmatically via the API, then track disposition through every stage.

Lattice file transfer files view

Inspect every file in a transfer

Switch to the files view to see individual file metadata, hashes, and disposition within each ticket. Search and filter across your entire transfer history.

Lattice ticket provenance view showing cross-domain file flow across the data diode

See exactly where every file has been

The provenance view shows where each file is in the pipeline: upload, JWT authorization, packaging, diode crossing, inspection, AV, human review, and release. Every event is hash-chained so you have a tamper-evident custody record from processing through storage. When something needs attention, quarantine or release a file, find it on disk, or jump straight to the failure.

Lattice Reliable Human Review queue overview

Reliable Human Review when policy demands it

RHR queues let operators triage inbound transfers before release. Policy routes files by extension, size, or uploader into named queues with configurable priorities and expiration times. Assign reviewers to queues by mission set, role, or other criteria — then triage, comment, detect duplicates, and approve or deny.

Lattice RHR ticket review with approve and disapprove actions

Policy-enforced approval workflows

Each review item shows ticket metadata, priority, assignment history, and a full activity log. Because RHR lives inside Lattice, reviewers collaborate right where the files and audit record are — no handoff to a separate ticketing system or integration to maintain. Comment, notify, attest, and approve or deny without breaking the custody chain.

Lattice admin users management view

Users, roles, and audit at your fingertips

Manage users and roles, configure RHR policies and queue labels, tune upload limits and inspection thresholds, and review the full audit log. Custom roles let you compose permission bundles for reviewers, operators, and admins.

Built for air-gapped operations

Lattice is the operations console for your protected enclave — deployed at the hardware-enforced boundary where your security policy meets unidirectional links.

Protected network

Where Lattice runs

  • Ticket-based file transfer
  • Content inspection & AV
  • Reliable Human Review
  • ENS pipeline orchestration
  • Tamper-evident audit

Hardware boundary

Expanse data diode

  • Physics-enforced one-way flow
  • No reverse path
  • Ingress or egress per policy
  • SFP+ fiber link

Common questions

What is Lattice?

Lattice is Domain Systems' cross-domain solution software platform. It provides a unified web console for ticket-based file transfer, ENS connection orchestration, content inspection, Reliable Human Review, provenance tracking, RBAC, and tamper-evident audit — built for critical infrastructure and high-assurance environments.

What is Reliable Human Review (RHR)?

RHR is Lattice's human-in-the-loop workflow on the air-gapped network. Clean inbound files can be held in staging until a reviewer in an assigned queue approves release. Policy routes files by extension, size, or uploader; reviewers can assign, comment, detect duplicates, and attest to decisions. Download-before-approve is optional per deployment.

How does Lattice differ from the Expanse Network Stack?

ENS is the modular toolkit of command-line utilities for protocol bridging across a data diode. Lattice is the enterprise platform that orchestrates ENS through a web UI, manages ticket-based file transfer with JWT authorization, enforces review and inspection policy, and provides provenance and audit trails.

How does file transfer authorization work?

Transfers require an approved ticket. Lattice cryptographically authorizes each movement before data crosses your boundary, with revocation tracked so pulled approvals are honored. Files pass content inspection and AV scanning on the protected side and may enter RHR before release to authorized users.

What authentication options does Lattice support?

Lattice supports local accounts (Argon2id-hashed, with admin approval before first login) or LDAP/AD with group filtering. Email-based login and verification are available. Sessions support idle timeout and remember-me. Personal access tokens with scoped permissions can be enabled for API and automation use cases.

How does content inspection work?

An optional shared inspection pipeline runs magic-byte detection, MIME/extension consistency checks, Google Magika ML file typing with configurable certainty thresholds, and dirty-word filtering. On the air-gapped side, inspection runs before AV scanning. On the external network, pre-upload rejection is available. Policy violations can block, warn, or quarantine with documented reason codes.

What is mTLS non-repudiation?

When enabled, uploads and optionally downloads require a valid TLS client certificate. Lattice records the certificate fingerprint or subject DN on every transfer and carries it across the diode in the transfer manifest. This cryptographically binds file movement to an identity — supporting CAC, YubiKey, and software certificates via nginx mTLS termination.

How is Lattice deployed?

Lattice deploys on hosts within your protected enclave at the data diode boundary, alongside Expanse hardware that enforces one-way flow. Production distributions use hardened containers with optional mTLS, suitable for air-gapped deployments.

Lattice works with Expanse hardware and ENS for complete physical enforcement.

Ready to deploy a complete cross-domain solution?

Schedule a demo to see the Lattice console in action.