Developer Security Infrastructure
Lateos builds purpose-built tools for developers who need to move fast without cutting corners on security or reliability. Open source, engineered, auditable.
Products
Security Tools
Detect malicious npm packages before they reach your codebase. Static analysis of typosquatting, infostealers, lifecycle hooks, and supply chain attacks.
Database Tools
PostgreSQL schema migrations with confidence. Risk assessment, rollback capability, AI-powered analysis. Fork of djrobstep/migra, actively maintained.
Coming soon: pgAudit (PostgreSQL compliance wrapper), WAL-G & pgBackRest forks (backup automation). Let's talk →
Philosophy
Each tool does one job exceptionally well. No bloat. No feature creep. Supply chain security. Schema migrations. Not a platform.
Full test suites. Documented failure modes. Security tooling demands reliability under pressure. If it can't be tested, it doesn't ship.
Community use is free forever. No code gatekeeping. No SaaS lock-in. All features for everyone. Companies pay fairly via Business License Agreement.
Every record carries traceable legal provenance. MIT, Apache 2.0, permissive vendor docs. Built to survive enterprise legal diligence.
Run locally. Full control. No hosted services required. Your data stays yours. No surprise pricing. No cloud migration required.
We measure success in hours recovered and risks prevented — not model parameters or leaderboard positions. Concrete, measurable outcomes.
Research
OT/ICS/SCADA Security — Attack Surface Analysis
Layer-by-layer technical breakdown of industrial control system vulnerabilities: protocol-layer weaknesses (Modbus, DNP3, legacy CIP), device-firmware exposure, architectural erosion under IT/OT convergence, MSP/RMM compromise, and human-layer targeting. Grounded in CISA advisories, NSA/FBI/DOE joint statements, and documented APT tradecraft (Volt Typhoon pre-positioning).
6 attack surfaces · 10+ CISA advisories · MITRE ATT&CK for ICS · Volt Typhoon TTPsGPT-OSS-120B — Indirect Prompt Injection Assessment
Red team evaluation across 250 test cases (25 IPI classes × 10 variants). 8% overall susceptibility with critical findings in 4 specific classes (IPI-010, IPI-019, IPI-021, IPI-022). Variant analysis: direct 9%, obfuscated 9.3%, embedded 5.3%. Structural disclosure with architectural root cause analysis and defensive validation patterns.
8% susceptibility · 250 test cases · 25 IPI classes · 4 vulnerable classesGPT-5 Nano — Prompt Injection Susceptibility Assessment
IPI Taxonomy v0.13 evaluation across 210 test cases (21 classes × 10 variants; 9 inference failures excluded; 201 analyzed). 38.3% overall susceptibility rate. Critical findings in recursive instruction framing (100%) and MCP tool description poisoning (80%). Full OWASP LLM mapping with defensive mitigations and validation unit-tests. Structural disclosure — no payloads published.
38.3% susceptibility · IPI-010 100% rate · OWASP LLM Top 10 mapped · Structural disclosureAbout
Leo Chongolnee
Founder & CEO · Lateos
Eight years at Philips Healthcare integrating mission-critical patient monitoring systems — PIIC ix, IntelliVue, and Tempus product lines — across regulated hospital environments governed by NFPA, TJC, and AAMI compliance standards. This is high-stakes infrastructure where patient safety, clinical data integrity, and zero-tolerance failure modes define every engineering decision.
Formal security credentials grounded that experience: CISSP (#551678), CEH, CCNA Security, AWS Certified Cloud Practitioner, and an M.S. in Management Information Systems (Enterprise Security) from the University of Arizona. These aren't decorative — they represent years of disciplined study across healthcare compliance frameworks, FHIR/HL7 integration, and supply chain security, areas where failures have real consequences. I've also shipped production iOS applications including Muawin AI and Cam2PDF Pro.
Philips taught me that infrastructure reliability and security aren't buzzwords — they're survival requirements. That's why Lateos builds tools that excel at one job and run reliably in production. No hype. Engineered discipline. npm-scan (2,000+ weekly downloads) and MigraDiff validate the approach. Current focus: expanding the database tools portfolio with pgAudit, WAL-G, and pgBackRest forks.