See the stars

LatticePay Specification

Home / LatticePay / LatticePay Specification

LatticePay

Tools for Trade, Not Surveillance.


LatticePay is an open-source payment infrastructure specification designed to provide private, encrypted, local-first commerce without unnecessary surveillance, centralized data control, or vendor lock-in.

LatticePay is designed as infrastructure rather than a centralized payment service. It enables merchants, developers, organizations, and communities to operate payment systems under their own control while supporting interoperable payment rails, distributed operation, and offline commerce.

Purpose

LatticePay is designed to establish an open foundation for payment and commerce systems that:

  • Protect transaction and merchant data through encryption by default
  • Support local-first and offline-capable commerce
  • Give merchants control over their payment infrastructure and transaction records
  • Support multiple payment and settlement methods through modular plugins
  • Enable peer-to-peer and federated commerce infrastructure
  • Minimize unnecessary collection and exposure of sensitive information
  • Provide verifiable transaction records without requiring centralized surveillance
  • Avoid proprietary payment infrastructure lock-in
  • Support extensibility for future payment technologies
  • Preserve transparency through open-source development and auditable protocols

Core Modules

Payment Processing Module

The Payment Processing Module provides the mechanisms required to initiate, authorize, record, reconcile, refund, and reverse payment transactions.

Features include:

  • Tap payment support
  • QR payment support
  • Invoice-based payments
  • Manual payment entry
  • Payment authorization
  • Payment confirmation
  • Transaction status tracking
  • Real-time settlement support
  • Deferred settlement support
  • Partial payment processing
  • Split tender payments
  • Merchant-to-merchant payments
  • Refund processing
  • Reversal processing
  • Cryptographic linkage between related transactions
  • Multi-currency transaction support
  • Offline transaction creation
  • Offline transaction signing
  • Transaction reconciliation
  • Duplicate transaction detection
  • Transaction state validation

Encryption & Privacy Module

The Encryption & Privacy Module protects sensitive commerce information throughout the transaction lifecycle.

Features include:

  • End-to-end encryption by default
  • Client-side encryption before transmission
  • Encrypted transaction payloads
  • Encrypted receipts
  • Encrypted merchant records
  • Encrypted customer information where retained
  • Forward-secret session keys
  • Cryptographic key rotation
  • Cryptographic identity
  • Digital signatures
  • Secure key management
  • Data minimization
  • Optional pseudonymous transaction identities
  • Optional privacy-preserving payment validation
  • Protection against unauthorized transaction disclosure
  • Separation of transaction authorization from unnecessary personal information

The system is designed so that encryption is a foundational property of the protocol rather than an optional add-on.

Identity & Authorization Module

The Identity & Authorization Module provides cryptographic identities and access controls without requiring a centralized identity provider.

Features include:

  • Cryptographic merchant identities
  • Cryptographic device identities
  • Cryptographic user identities where required
  • Digital signatures
  • Device authorization
  • Merchant authorization
  • Role-based permissions
  • Key-based access control
  • Key rotation
  • Credential revocation
  • Multi-device authorization
  • Delegated authorization
  • Session authentication
  • Optional pseudonymous identities

Identity information should only be collected or retained when required for the applicable transaction, payment rail, legal obligation, or merchant-selected function.

Local-First Commerce Module

The Local-First Commerce Module enables LatticePay to operate without continuous access to a centralized server.

Features include:

  • Local transaction processing
  • Local transaction storage
  • Offline POS operation
  • Offline payment workflows where supported by the selected payment rail
  • Local receipt generation
  • Local inventory access
  • Local merchant administration
  • Deferred synchronization
  • Automatic synchronization when connectivity returns
  • Local recovery mechanisms
  • Operation during temporary network outages
  • Merchant-controlled local data

Local operation is treated as a core architectural capability rather than a fallback mode.

Ledger & Accounting Module

The Ledger & Accounting Module provides a deterministic record of commerce activity.

Features include:

  • Append-only transaction records
  • Transaction timestamps
  • Transaction identifiers
  • Transaction state history
  • Cryptographic transaction signatures
  • Tamper-evident records
  • Hash-linked transaction relationships
  • Deterministic reconciliation
  • Multi-device ledger synchronization
  • Account and balance tracking
  • Refund and reversal linkage
  • Merchant-controlled accounting records
  • Accounting data export
  • Transaction history search
  • Financial reporting support
  • Audit trail generation

The ledger is designed to preserve transaction integrity while limiting unnecessary disclosure of transaction information.

Synchronization Module

The Synchronization Module coordinates commerce data across authorized devices and nodes.

Features include:

  • Local-to-local synchronization
  • Device-to-device synchronization
  • Merchant node synchronization
  • Offline synchronization
  • Conflict detection
  • Conflict resolution
  • Distributed state reconciliation
  • Deterministic state convergence
  • Encrypted synchronization
  • Selective synchronization
  • Authorized peer discovery
  • Recovery after interrupted synchronization

Synchronization must preserve transaction integrity and must not require exposing plaintext transaction data to unauthorized infrastructure.

Network & Federation Module

The Network & Federation Module provides decentralized communication and optional federation between independently operated LatticePay systems.

Features include:

  • Peer-to-peer communication
  • Encrypted node communication
  • Merchant-controlled nodes
  • Community-operated nodes
  • Federated merchant networks
  • Authorized peer relationships
  • Node discovery
  • Node authentication
  • Secure synchronization
  • Network resilience
  • Interoperable federation
  • Independent deployment
  • Optional disconnected operation

Federation is optional. A merchant must be able to operate independently without joining a shared network.

POS & Merchant Operations Module

The POS & Merchant Operations Module provides the operational tools required to conduct everyday commerce.

Features include:

  • Point-of-sale transaction processing
  • Product entry
  • Product lookup
  • Cart management
  • Tax calculation
  • Discounts
  • Customer-selected payment methods
  • Receipt generation
  • Refund processing
  • Transaction lookup
  • Cash drawer support
  • Register management
  • Multi-register operation
  • Multi-device operation
  • Merchant administration
  • Employee permissions
  • Shift management
  • Sales summaries
  • Daily transaction summaries
  • Offline operation

Inventory Module

The Inventory Module provides merchant inventory management capabilities.

Features include:

  • Product records
  • Product identifiers
  • Product pricing
  • Stock quantities
  • Inventory adjustments
  • Low-stock indicators
  • Inventory synchronization
  • Product categories
  • Product search
  • Stock movement history
  • Inventory reporting
  • Multi-location inventory support
  • Optional integration with external inventory systems

Invoicing Module

The Invoicing Module provides encrypted invoice creation and payment tracking.

Features include:

  • Invoice creation
  • Invoice numbering
  • Line-item management
  • Tax and discount calculations
  • Payment status tracking
  • Partial invoice payments
  • Invoice expiration
  • Encrypted invoice delivery
  • Digital receipts
  • Invoice history
  • Refund linkage
  • Merchant-controlled invoice records
  • Exportable invoice records

Receipt & Commerce Records Module

The Receipt & Commerce Records Module manages transaction documentation.

Features include:

  • Digital receipts
  • Encrypted receipts
  • Printable receipts
  • Receipt delivery
  • Receipt verification
  • Transaction-linked receipts
  • Refund receipts
  • Invoice-linked receipts
  • Merchant-controlled receipt storage
  • Customer-selected receipt delivery methods
  • Exportable transaction documentation

Merchant Data Ownership Module

The Merchant Data Ownership Module establishes merchant control over operational and transaction data.

Features include:

  • Merchant-controlled data storage
  • Local data ownership
  • Encrypted records
  • Data export
  • Data portability
  • Data deletion controls where legally and technically appropriate
  • Selective data sharing
  • Access controls
  • No mandatory centralized analytics
  • No behavioral profiling
  • No data brokerage
  • No required third-party data warehouse

Security & Audit Module

The Security & Audit Module provides mechanisms for detecting unauthorized changes and reviewing system activity.

Features include:

  • Cryptographically verifiable transactions
  • Tamper-evident records
  • Signed events
  • Security event logging
  • Authorization event logging
  • Administrative audit trails
  • Integrity verification
  • Transaction verification
  • Key lifecycle auditing
  • Reconciliation auditing
  • Exportable audit records
  • Privacy-preserving audit capabilities

Audit functionality must avoid creating unnecessary centralized surveillance of merchants or customers.


Optional Plugin Modules

LatticePay uses a modular plugin model so payment rails, settlement systems, and specialized commerce capabilities can be added without modifying the core protocol.

Card Payment Plugin

Provides integration with external card payment processors and card network services.

Potential capabilities include:

  • Card authorization
  • Card-present transactions
  • Contactless payments
  • Tokenized card payments
  • Processor communication
  • Settlement reporting
  • Refund processing
  • Chargeback event handling
  • External processor reconciliation

Card processing remains an external payment rail and does not require LatticePay itself to become a card network.

Bank Transfer Plugin

Provides integration with supported banking and electronic transfer systems.

Potential capabilities include:

  • Bank transfer initiation
  • Account verification
  • Transfer status tracking
  • Settlement confirmation
  • Reconciliation
  • Refund support
  • External banking system integration

ACH Plugin

Provides integration with supported ACH payment services.

Potential capabilities include:

  • ACH payment initiation
  • ACH authorization workflows
  • Settlement tracking
  • Return handling
  • Reconciliation
  • Refund workflows
  • Merchant reporting

SEPA Plugin

Provides integration with supported SEPA payment services.

Potential capabilities include:

  • SEPA transfer initiation
  • Payment status tracking
  • Settlement confirmation
  • Reconciliation
  • Refund support

Digital Currency Plugin

Provides optional integration with supported digital currency and digital cash systems.

Potential capabilities include:

  • Digital currency payments
  • Wallet integration
  • Transaction verification
  • Settlement tracking
  • Exchange integration
  • Refund workflows
  • Merchant-selected currency support

Peer-to-Peer Settlement Plugin

Provides direct settlement between participating merchants or authorized participants.

Potential capabilities include:

  • Merchant-to-merchant settlement
  • Cryptographic payment authorization
  • Peer discovery
  • Settlement confirmation
  • Transaction reconciliation
  • Offline settlement workflows where supported

Subscription Plugin

Provides optional recurring payment functionality.

Potential capabilities include:

  • Subscription creation
  • Recurring payment schedules
  • Payment authorization
  • Subscription status tracking
  • Cancellation
  • Renewal
  • Failed-payment handling
  • Merchant-controlled subscription records

Tax & Compliance Plugin

Provides optional tools for jurisdiction-specific commerce requirements.

Potential capabilities include:

  • Tax calculation
  • Tax classification
  • Tax reporting
  • Jurisdiction-specific rules
  • Compliance record generation
  • Exportable reporting

Compliance functionality must remain modular because requirements vary by jurisdiction and payment rail.

Accounting Integration Plugin

Provides optional integration with external accounting systems.

Potential capabilities include:

  • Transaction export
  • Ledger synchronization
  • Account mapping
  • Reconciliation
  • Financial reporting
  • Tax reporting
  • Merchant-selected accounting integrations

Hardware Integration Plugin

Provides optional integration with supported payment and commerce hardware.

Potential capabilities include:

  • Payment terminals
  • Card readers
  • Barcode scanners
  • Receipt printers
  • Cash drawers
  • Customer displays
  • Inventory scanners
  • Embedded commerce devices

Hardware integrations must not create mandatory proprietary hardware dependencies.

Analytics Plugin

Provides optional merchant-controlled business analytics without making surveillance analytics part of the core system.

Potential capabilities include:

  • Sales reporting
  • Product performance
  • Inventory analysis
  • Revenue trends
  • Merchant-defined reporting
  • Local analytics
  • Privacy-preserving aggregate reporting

Analytics must remain opt-in and merchant-controlled.

Payment Rail Abstraction

LatticePay separates the core commerce protocol from external payment rails.

Payment rails are treated as replaceable modules rather than permanent dependencies.

The abstraction layer is designed to support:

  • Multiple payment providers
  • Multiple currencies
  • Multiple settlement systems
  • Multiple payment instruments
  • Merchant-selected providers
  • Provider replacement
  • Payment rail-specific authorization
  • Payment rail-specific settlement
  • Payment rail-specific reconciliation
  • Independent evolution of payment integrations

The core LatticePay system must not require a single payment provider for basic operation.

Offline Commerce

LatticePay is designed to support commerce during temporary or complete network interruptions where the selected payment method permits offline operation.

Offline capabilities include:

  • Local transaction creation
  • Local transaction signing
  • Local receipt generation
  • Local ledger updates
  • Deferred synchronization
  • Transaction queueing
  • Conflict detection
  • Reconciliation after reconnection
  • Recovery from interrupted synchronization

Offline payment behavior must account for the trust, risk, authorization, and settlement characteristics of the selected payment rail.


Specification Branding License (SBL)

Standard

Optional


License & Notice Requirements

LatticePay is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

By contributing to this project, you agree that your contributions will also be released under this license.

Please note the following:

  • All contributions must comply with the AGPL-3.0+ terms.
  • Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to: Roxanne Ardary and roxanneardary.com.
  • LatticePay specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
  • The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update notice.md.
  • When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
  • Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.

For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.


Notice – LatticePay

Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.

Contributors

This file tracks contributors and their specific contributions to the project.

  • Roxanne Ardary, roxanneardary.com – May 30, 2026
    Created the repository for LatticePay. Designed the foundational architecture for an open-source, privacy-first, encrypted payment infrastructure including core protocol direction, system design principles, and initial project structure.
  • [Add other contributors here] – [Date]
    [Describe contribution in one sentence]

License – LatticePay

This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

Key Points:

  • You are free to use, modify, and distribute the code.
  • All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
  • The software is provided “as is,” without warranty of any kind.

For the full license text, see GNU AGPL-3.0 License: https://www.gnu.org/licenses/agpl-3.0.html