Home / LatticePay / LatticePay Specification
LatticePay
Tools for Trade, Not Surveillance.
LatticePay is an open-source payment infrastructure specification designed to provide private, encrypted, local-first commerce without unnecessary surveillance, centralized data control, or vendor lock-in.
LatticePay is designed as infrastructure rather than a centralized payment service. It enables merchants, developers, organizations, and communities to operate payment systems under their own control while supporting interoperable payment rails, distributed operation, and offline commerce.
Purpose
LatticePay is designed to establish an open foundation for payment and commerce systems that:
- Protect transaction and merchant data through encryption by default
- Support local-first and offline-capable commerce
- Give merchants control over their payment infrastructure and transaction records
- Support multiple payment and settlement methods through modular plugins
- Enable peer-to-peer and federated commerce infrastructure
- Minimize unnecessary collection and exposure of sensitive information
- Provide verifiable transaction records without requiring centralized surveillance
- Avoid proprietary payment infrastructure lock-in
- Support extensibility for future payment technologies
- Preserve transparency through open-source development and auditable protocols
Core Modules
Payment Processing Module
The Payment Processing Module provides the mechanisms required to initiate, authorize, record, reconcile, refund, and reverse payment transactions.
Features include:
- Tap payment support
- QR payment support
- Invoice-based payments
- Manual payment entry
- Payment authorization
- Payment confirmation
- Transaction status tracking
- Real-time settlement support
- Deferred settlement support
- Partial payment processing
- Split tender payments
- Merchant-to-merchant payments
- Refund processing
- Reversal processing
- Cryptographic linkage between related transactions
- Multi-currency transaction support
- Offline transaction creation
- Offline transaction signing
- Transaction reconciliation
- Duplicate transaction detection
- Transaction state validation
Encryption & Privacy Module
The Encryption & Privacy Module protects sensitive commerce information throughout the transaction lifecycle.
Features include:
- End-to-end encryption by default
- Client-side encryption before transmission
- Encrypted transaction payloads
- Encrypted receipts
- Encrypted merchant records
- Encrypted customer information where retained
- Forward-secret session keys
- Cryptographic key rotation
- Cryptographic identity
- Digital signatures
- Secure key management
- Data minimization
- Optional pseudonymous transaction identities
- Optional privacy-preserving payment validation
- Protection against unauthorized transaction disclosure
- Separation of transaction authorization from unnecessary personal information
The system is designed so that encryption is a foundational property of the protocol rather than an optional add-on.
Identity & Authorization Module
The Identity & Authorization Module provides cryptographic identities and access controls without requiring a centralized identity provider.
Features include:
- Cryptographic merchant identities
- Cryptographic device identities
- Cryptographic user identities where required
- Digital signatures
- Device authorization
- Merchant authorization
- Role-based permissions
- Key-based access control
- Key rotation
- Credential revocation
- Multi-device authorization
- Delegated authorization
- Session authentication
- Optional pseudonymous identities
Identity information should only be collected or retained when required for the applicable transaction, payment rail, legal obligation, or merchant-selected function.
Local-First Commerce Module
The Local-First Commerce Module enables LatticePay to operate without continuous access to a centralized server.
Features include:
- Local transaction processing
- Local transaction storage
- Offline POS operation
- Offline payment workflows where supported by the selected payment rail
- Local receipt generation
- Local inventory access
- Local merchant administration
- Deferred synchronization
- Automatic synchronization when connectivity returns
- Local recovery mechanisms
- Operation during temporary network outages
- Merchant-controlled local data
Local operation is treated as a core architectural capability rather than a fallback mode.
Ledger & Accounting Module
The Ledger & Accounting Module provides a deterministic record of commerce activity.
Features include:
- Append-only transaction records
- Transaction timestamps
- Transaction identifiers
- Transaction state history
- Cryptographic transaction signatures
- Tamper-evident records
- Hash-linked transaction relationships
- Deterministic reconciliation
- Multi-device ledger synchronization
- Account and balance tracking
- Refund and reversal linkage
- Merchant-controlled accounting records
- Accounting data export
- Transaction history search
- Financial reporting support
- Audit trail generation
The ledger is designed to preserve transaction integrity while limiting unnecessary disclosure of transaction information.
Synchronization Module
The Synchronization Module coordinates commerce data across authorized devices and nodes.
Features include:
- Local-to-local synchronization
- Device-to-device synchronization
- Merchant node synchronization
- Offline synchronization
- Conflict detection
- Conflict resolution
- Distributed state reconciliation
- Deterministic state convergence
- Encrypted synchronization
- Selective synchronization
- Authorized peer discovery
- Recovery after interrupted synchronization
Synchronization must preserve transaction integrity and must not require exposing plaintext transaction data to unauthorized infrastructure.
Network & Federation Module
The Network & Federation Module provides decentralized communication and optional federation between independently operated LatticePay systems.
Features include:
- Peer-to-peer communication
- Encrypted node communication
- Merchant-controlled nodes
- Community-operated nodes
- Federated merchant networks
- Authorized peer relationships
- Node discovery
- Node authentication
- Secure synchronization
- Network resilience
- Interoperable federation
- Independent deployment
- Optional disconnected operation
Federation is optional. A merchant must be able to operate independently without joining a shared network.
POS & Merchant Operations Module
The POS & Merchant Operations Module provides the operational tools required to conduct everyday commerce.
Features include:
- Point-of-sale transaction processing
- Product entry
- Product lookup
- Cart management
- Tax calculation
- Discounts
- Customer-selected payment methods
- Receipt generation
- Refund processing
- Transaction lookup
- Cash drawer support
- Register management
- Multi-register operation
- Multi-device operation
- Merchant administration
- Employee permissions
- Shift management
- Sales summaries
- Daily transaction summaries
- Offline operation
Inventory Module
The Inventory Module provides merchant inventory management capabilities.
Features include:
- Product records
- Product identifiers
- Product pricing
- Stock quantities
- Inventory adjustments
- Low-stock indicators
- Inventory synchronization
- Product categories
- Product search
- Stock movement history
- Inventory reporting
- Multi-location inventory support
- Optional integration with external inventory systems
Invoicing Module
The Invoicing Module provides encrypted invoice creation and payment tracking.
Features include:
- Invoice creation
- Invoice numbering
- Line-item management
- Tax and discount calculations
- Payment status tracking
- Partial invoice payments
- Invoice expiration
- Encrypted invoice delivery
- Digital receipts
- Invoice history
- Refund linkage
- Merchant-controlled invoice records
- Exportable invoice records
Receipt & Commerce Records Module
The Receipt & Commerce Records Module manages transaction documentation.
Features include:
- Digital receipts
- Encrypted receipts
- Printable receipts
- Receipt delivery
- Receipt verification
- Transaction-linked receipts
- Refund receipts
- Invoice-linked receipts
- Merchant-controlled receipt storage
- Customer-selected receipt delivery methods
- Exportable transaction documentation
Merchant Data Ownership Module
The Merchant Data Ownership Module establishes merchant control over operational and transaction data.
Features include:
- Merchant-controlled data storage
- Local data ownership
- Encrypted records
- Data export
- Data portability
- Data deletion controls where legally and technically appropriate
- Selective data sharing
- Access controls
- No mandatory centralized analytics
- No behavioral profiling
- No data brokerage
- No required third-party data warehouse
Security & Audit Module
The Security & Audit Module provides mechanisms for detecting unauthorized changes and reviewing system activity.
Features include:
- Cryptographically verifiable transactions
- Tamper-evident records
- Signed events
- Security event logging
- Authorization event logging
- Administrative audit trails
- Integrity verification
- Transaction verification
- Key lifecycle auditing
- Reconciliation auditing
- Exportable audit records
- Privacy-preserving audit capabilities
Audit functionality must avoid creating unnecessary centralized surveillance of merchants or customers.
Optional Plugin Modules
LatticePay uses a modular plugin model so payment rails, settlement systems, and specialized commerce capabilities can be added without modifying the core protocol.
Card Payment Plugin
Provides integration with external card payment processors and card network services.
Potential capabilities include:
- Card authorization
- Card-present transactions
- Contactless payments
- Tokenized card payments
- Processor communication
- Settlement reporting
- Refund processing
- Chargeback event handling
- External processor reconciliation
Card processing remains an external payment rail and does not require LatticePay itself to become a card network.
Bank Transfer Plugin
Provides integration with supported banking and electronic transfer systems.
Potential capabilities include:
- Bank transfer initiation
- Account verification
- Transfer status tracking
- Settlement confirmation
- Reconciliation
- Refund support
- External banking system integration
ACH Plugin
Provides integration with supported ACH payment services.
Potential capabilities include:
- ACH payment initiation
- ACH authorization workflows
- Settlement tracking
- Return handling
- Reconciliation
- Refund workflows
- Merchant reporting
SEPA Plugin
Provides integration with supported SEPA payment services.
Potential capabilities include:
- SEPA transfer initiation
- Payment status tracking
- Settlement confirmation
- Reconciliation
- Refund support
Digital Currency Plugin
Provides optional integration with supported digital currency and digital cash systems.
Potential capabilities include:
- Digital currency payments
- Wallet integration
- Transaction verification
- Settlement tracking
- Exchange integration
- Refund workflows
- Merchant-selected currency support
Peer-to-Peer Settlement Plugin
Provides direct settlement between participating merchants or authorized participants.
Potential capabilities include:
- Merchant-to-merchant settlement
- Cryptographic payment authorization
- Peer discovery
- Settlement confirmation
- Transaction reconciliation
- Offline settlement workflows where supported
Subscription Plugin
Provides optional recurring payment functionality.
Potential capabilities include:
- Subscription creation
- Recurring payment schedules
- Payment authorization
- Subscription status tracking
- Cancellation
- Renewal
- Failed-payment handling
- Merchant-controlled subscription records
Tax & Compliance Plugin
Provides optional tools for jurisdiction-specific commerce requirements.
Potential capabilities include:
- Tax calculation
- Tax classification
- Tax reporting
- Jurisdiction-specific rules
- Compliance record generation
- Exportable reporting
Compliance functionality must remain modular because requirements vary by jurisdiction and payment rail.
Accounting Integration Plugin
Provides optional integration with external accounting systems.
Potential capabilities include:
- Transaction export
- Ledger synchronization
- Account mapping
- Reconciliation
- Financial reporting
- Tax reporting
- Merchant-selected accounting integrations
Hardware Integration Plugin
Provides optional integration with supported payment and commerce hardware.
Potential capabilities include:
- Payment terminals
- Card readers
- Barcode scanners
- Receipt printers
- Cash drawers
- Customer displays
- Inventory scanners
- Embedded commerce devices
Hardware integrations must not create mandatory proprietary hardware dependencies.
Analytics Plugin
Provides optional merchant-controlled business analytics without making surveillance analytics part of the core system.
Potential capabilities include:
- Sales reporting
- Product performance
- Inventory analysis
- Revenue trends
- Merchant-defined reporting
- Local analytics
- Privacy-preserving aggregate reporting
Analytics must remain opt-in and merchant-controlled.
Payment Rail Abstraction
LatticePay separates the core commerce protocol from external payment rails.
Payment rails are treated as replaceable modules rather than permanent dependencies.
The abstraction layer is designed to support:
- Multiple payment providers
- Multiple currencies
- Multiple settlement systems
- Multiple payment instruments
- Merchant-selected providers
- Provider replacement
- Payment rail-specific authorization
- Payment rail-specific settlement
- Payment rail-specific reconciliation
- Independent evolution of payment integrations
The core LatticePay system must not require a single payment provider for basic operation.
Offline Commerce
LatticePay is designed to support commerce during temporary or complete network interruptions where the selected payment method permits offline operation.
Offline capabilities include:
- Local transaction creation
- Local transaction signing
- Local receipt generation
- Local ledger updates
- Deferred synchronization
- Transaction queueing
- Conflict detection
- Reconciliation after reconnection
- Recovery from interrupted synchronization
Offline payment behavior must account for the trust, risk, authorization, and settlement characteristics of the selected payment rail.
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system
- Copyleft enforced for network deployments
- Required attribution:
- Roxanne Ardary
- https://www.roxanneardary.com/
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment
- Pricing based on scale, usage, and deployment scope
- https://roxanneardary.com/latticepay/
License & Notice Requirements
LatticePay is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to this project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to: Roxanne Ardary and roxanneardary.com.
- LatticePay specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update
notice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – LatticePay
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com – May 30, 2026
Created the repository for LatticePay. Designed the foundational architecture for an open-source, privacy-first, encrypted payment infrastructure including core protocol direction, system design principles, and initial project structure. - [Add other contributors here] – [Date]
[Describe contribution in one sentence]
License – LatticePay
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points:
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License: https://www.gnu.org/licenses/agpl-3.0.html
