Skip to main content

Changelog

Follow new updates and improvements to Lamatic.ai.

Handle documents with ease: Merge, split, and edit PDFs right from your flow

You have a flow that generates a report. Now you need to staple a cover page to the front, drop the internal-only appendix, and stamp the client's name in the document title. None of that is AI work; it's plumbing, but until now it meant chaining nodes, writing a Code node, or handing the file off to an external service and waiting for it to come back.

The Document Handling node handles each of those directly. Point it at a PDF, pick the operation, get a file back. No Code node, no round trip to an external service.

What it does

The Document Handling node has 14 different functionalities that you most frequently need combined into one node :

Merge (1)

  • Merge: combine multiple PDFs in order, with optional per-document page ranges and bookmark preservation

Split (3)

  • Every N pages: one file per N-page chunk

  • At specific page numbers: split exactly where you choose

  • Every page: one file per page

Pages (5)

  • Extract: pull selected pages into a new document

  • Delete: remove selected pages

  • Insert blank pages: add blank pages at a chosen position

  • Insert from document: splice in pages from another PDF

  • Reorder / duplicate: rearrange pages, or repeat a page number to duplicate it

Bookmarks (3)

  • List: read the document's outline

  • Set: write a new outline, either replacing the existing one or adding to it

  • Remove: strip all bookmarks

Metadata (2)

  • Get: read title, author, subject, creator, and keywords

  • Set: write those fields

What this unlocks

  • Assemble a cover page, generated report, and appendix into one client-ready PDF.

  • Split a 400-page scan into chapters before sending it through extraction, so you're not OCRing the whole thing to read page 12.

  • Strip a boilerplate cover or splice a signed addendum into an existing contract.

  • Stamp metadata on every document a publishing pipeline produces.

  • Read a PDF's bookmark outline to figure out its structure before you decide how to chunk it.


How it works

Pick a Type first, then the operation for that type. You only see the fields that matter for what you're doing, no scrolling past twelve irrelevant inputs to find the one you need.

Documents go in as URLs and come out as URLs: every operation that produces a file returns a presigned URL plus a durable storage key, so the shape is the same every time and downstream nodes always know what to expect. Whole PDFs never land in your workflow state or your logs. List Bookmarks and Get Metadata return their data directly instead of a file.

Two things called out in the node UI so they don't surprise you: password-protected PDFs are rejected (Get Metadata is the exception; it can still read an encrypted document), and Extract, Insert, and ranged Merge can drop annotations, outlines, or form fields from the pages they touch.

Checkout the docs for more details.

New

Lamatic.ai Renews SOC 2 Type 2

Lamatic.ai has successfully renewed its SOC 2 Type 2 certification, completing its second consecutive annual examination conducted by Prescient Assurance LLC (Nashville, TN) for the period April 1 – July 15, 2026.

Renewal matters. A single SOC 2 report tells you our controls were designed correctly. A renewed report tells you they kept working through infrastructure changes, team changes, and a significantly expanded scope. This cycle is our most comprehensive yet: we expanded coverage to three Trust Service Criteria, overhauled our infrastructure stack, and brought in best-in-class compliance partners to make the audit process more rigorous and repeatable.


Three Trust Service Criteria, Now Verified

Our previous certification covered Security alone. This renewal adds Confidentiality and Availability, two criteria that enterprise and regulated-industry customers consistently ask about in procurement.

Security: Controls protect the Lamatic platform against unauthorized access, threats, and vulnerabilities. This includes role-based access control, MFA enforcement, annual penetration testing, and continuous automated vulnerability scanning.

Confidentiality: Customer data and information subject to confidentiality agreements are handled, stored, and disposed of in accordance with documented policies. Employees and contractors are bound by NDAs, and data access is governed by least-privilege principles reviewed quarterly.

Availability: The platform is monitored around the clock with real-time dashboards and alerting. Incident response procedures are documented and tested. Backups are encrypted at rest and maintained across redundant providers.

An independent auditor reviewed our controls and confirmed they operated effectively throughout the entire audit period, not just at a point in time.

You can view our real-time compliance posture at trust.lamatic.ai.


New Stack Vendors: Hardened for Performance and Security

This renewal cycle coincided with meaningful upgrades to the Lamatic infrastructure stack. Several new vendors were brought in specifically to raise the performance and security bar, and all were fully in scope for the auditor's testing.

  • DigitalOcean (primary cloud): All production workloads and managed databases now run on DigitalOcean with tenant-isolated infrastructure as a core design principle, replacing GCP as the primary provider.

  • Aikido Security: Consolidated all security scanning into a single platform covering SAST, SCA, DAST, container scanning, IaC scanning, and developer device monitoring. Replaced separate Deepsource and Snyk tools.

  • Grafana: Centralized observability across all infrastructure components, aggregating metrics, logs, and traces with real-time dashboards and incident alerting.

  • ClickHouse: High-performance analytics database for platform data, replacing legacy infrastructure.

  • Weaviate: Vector database powering AI agent memory, fully in-scope for data security and availability controls.

  • Cloudflare WAF/CDN: Network-layer protection with DDoS mitigation across all production endpoints.

Controls were assessed against the live system with all new vendors in place, not a pre-change snapshot.


Our Security and Compliance Partners

Building a rigorous compliance program as a lean team requires the right partners. Here's who we worked with and what role each played:

Vanta: Compliance automation and continuous control monitoring. Vanta powers our ISMS, tracks evidence collection across all in-scope systems, and keeps our control posture current between audits. It's the operational backbone that makes ongoing compliance sustainable, not a once-a-year scramble. Our live trust page at trust.lamatic.ai is powered by Vanta and shows real-time control status to anyone who needs it.

Aikido Security: Our security testing platform. Beyond continuous scanning, Aikido monitors developer devices and flags vulnerabilities across our entire codebase and infrastructure in real time. It gave our auditors a live, verifiable evidence trail for security controls rather than point-in-time screenshots. You can request our Aikido security report directly at aikido.dev/audit-report/lamatic.

Prescient Assurance LLC: Our independent SOC 2 auditor, based in Nashville, TN. Prescient conducted the Type 2 examination in accordance with AICPA attestation standards, reviewing both the design and operating effectiveness of our controls over the full audit period.


How We Used AI Agents to Run a More Rigorous Audit

As a platform built for AI agents, we practiced what we preach. This audit cycle was the first time we systematically used agents to accelerate and strengthen the internal audit process.

We deployed agents to cross-reference our SOC 2 system description against live Notion policy documents, flagging inconsistencies between attested controls and actual configurations before the auditor ever saw them. Agents reviewed the testing matrix for internally contradictory findings, tracked the status of every open non-conformity across our compliance database, and maintained real-time updates to our Internal Audit Report, Statement of Applicability, and System Description as the audit progressed.

The result: Our internal audit team caught and resolved gaps that would typically surface only during fieldwork, reducing back-and-forth with Prescient Assurance and compressing the overall audit timeline. This is the same capability we're building into the Lamatic platform for our customers.


Ready to Evaluate Lamatic

If you're evaluating Lamatic for an enterprise or regulated environment, here's how to access our security documentation:

  • Real-time compliance status: trust.lamatic.ai shows our live control posture, updated continuously.

  • Aikido security report: Request our automated security scan report at aikido.dev/audit-report/lamatic. No NDA required.

  • SOC 2 Type 2 report: The full Prescient Assurance report (testing matrix, subservice org disclosures, management assertion) is available under NDA. Reach out at hello@lamatic.ai or contact your account team directly.


Lamatic.ai is a product of Dinner Technologies, Inc. Prescient Assurance LLC conducted the SOC 2 Type 2 examination in accordance with the AICPA's attestation standards.

Global search is here, plus a cleaner sidebar

Global Search

Press the search shortcut (Ctrl/Cmd + K) or click the search icon anywhere in the app and jump straight to any section: Flows, Prompts, Data, Connections, Deployments, Jobs, API Playground, Logs, Reports grouped under Build, Deploy, and Monitor.

Type to filter, use arrow keys to navigate, hit Enter to go. No more hunting through the sidebar for something you know exists but can't remember where you tucked it.


Sidebar improvements

The sidebar's been reorganized around how you actually work: Build, Deploy, and Monitor as clear sections instead of one long flat list. We've also added quick access at the bottom for:

  • Book a Call to talk to the team directly

  • Help get support without leaving the app

  • Settings are now easier to reach


Try it in Studio →

Improved

Earlier updates