Developer Security Infrastructure
Lateos builds purpose-built tools for developers who need to move fast without cutting corners on security or reliability. Open source, engineered, auditable.
SOAR dataset · npm-scan · MigraDiff · Free training datasets →
Mission
LLM systems are increasingly critical to enterprise operations, yet they operate in hostile environments where prompt injection, indirect attacks, and data exfiltration are active threats. We conduct rigorous red team research and provide structural disclosure of vulnerabilities — engineering real mitigations that work under adversarial conditions, not marketing narratives.
Organizations need clean, verifiable datasets to test and validate their LLM defenses against real-world attack patterns. We provide golden training datasets with complete legal provenance — enabling security teams to validate defenses before production deployment, not after compromise.
Malicious packages, typosquatting, and lifecycle attacks bypass traditional scanning. We detect behavioral patterns and novel threats that signatures miss. PostgreSQL migrations, backup automation, and compliance tooling protect the infrastructure feeding LLM systems. Everything runs locally — no vendor lock-in, no cloud dependency, full control.
Full test coverage, documented threat models, and measurable outcomes. We optimize for concrete results — incident prevention, hours recovered, attack surface closed — not leaderboards or marketing metrics. MIT licensed, always free for community use. Business License ensures sustainable development and vendor accountability. If it can't be tested and verified, it doesn't ship.
Dataset
A quality-controlled corpus of executable SOAR security playbooks and threat-intel records, served to autonomous agents over a pay-per-query API. Every record is labeled for platform, executability, and blast radius — and the API monetizes itself: keyless agents receive an HTTP 402 machine-payment challenge with a Stripe checkout, and the webhook provisions the key. No human in the loop.
402
Machine payments (MPP)
Stripe MPP challenge in the 402 response, metered subscription checkout, webhook-provisioned API keys. The machine pays for itself.
MCP
Registered MCP server
ai.lateos/soar-record-gateway on the official MCP registry — streamable HTTP, discoverable by any MCP client.
AI
Agent-native contracts
llms.txt, OpenAPI, and AI plugin manifests — every endpoint documented for machines, not just humans.
DB
Edge-served & searchable
Full-text search (ts_rank_cd) over Neon PostgreSQL at the edge. Enterprise plans are unmetered.
About
Leo Chongolnee
Founder & CEO · Lateos
Eight years at Philips Healthcare integrating mission-critical patient monitoring systems — PIIC ix, IntelliVue, and Tempus product lines — across regulated hospital environments governed by NFPA, TJC, and AAMI compliance standards. This is high-stakes infrastructure where patient safety, clinical data integrity, and zero-tolerance failure modes define every engineering decision.
Formal security credentials grounded that experience: CISSP (#551678), CEH, CCNA Security, AWS Certified Cloud Practitioner, and an M.S. in Management Information Systems (Enterprise Security) from the University of Arizona. These aren't decorative — they represent years of disciplined study across healthcare compliance frameworks, FHIR/HL7 integration, and supply chain security, areas where failures have real consequences. I've also shipped production iOS applications including Muawin AI and Cam2PDF Pro.
Philips taught me that infrastructure reliability and security aren't buzzwords — they're survival requirements. That's why Lateos builds tools that excel at one job and run reliably in production. No hype. Engineered discipline. npm-scan (2,000+ weekly downloads) and MigraDiff validate the approach. Current focus: expanding the database tools portfolio with pgAudit, WAL-G, and pgBackRest forks.