The Security Trust Center is a central hub for compliance reports, security policies, and other resources. It provides transparency and access to essential security information.
Click the tabs at the top of the Security Trust Center to learn more about:
-
Resources: View and download compliance reports and redacted policies:
- PCI and SOC 3 compliance reports, which do not require an access request.
- Redacted information security policies, SOC 2 Type 2 compliance reports, penetration testing attestations, and the PCI Roles and Responsibilities Matrix, which require an access request.
- Controls: View Lightspeed’s organizational security and privacy controls.
- Subprocessors: Learn more about the subprocessors engaged by Lightspeed to process customer data and provide Lightspeed services.
- FAQ: Find additional information about the Security Trust Center and bug bounty program.
Some documents in the Resources section are access restricted and are not publicly viewable or downloadable. Access to these documents is reserved for existing merchants or prospective merchants who have a valid Non-Disclosure Agreement (NDA) in place with Lightspeed.
Understanding Payment Card Industry (PCI) reports
The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard designed to protect payment account data. It applies to entities that store, process, or transmit cardholder data or sensitive authentication data, as well as entities that could affect the security of the cardholder data environment.
The standard establishes consistent technical and operational security requirements for protecting payment account data. PCI reports document an organization’s PCI DSS assessment results and compliance status against the requirements maintained by the PCI Security Standards Council.
Available reports
PCI Attestation of Compliance (AoC)
The AoC is an official document confirming the results of Lightspeed’s annual PCI DSS compliance assessment. Lightspeed issues an updated AoC for each applicable platform after completing its annual assessment. These documents are publicly available through the Security Trust Center.
Understanding Service Organization Control (SOC 2) reports
Service Organization Control (SOC 2) reports evaluate an organization’s controls relevant to security, confidentiality, privacy, processing integrity, and availability. These reports are based on the Trust Services Criteria established and maintained by the American Institute of Certified Public Accountants (AICPA).
Available reports
SOC 3 report
The SOC 3 report provides a high-level, general-use summary of Lightspeed’s controls relevant to the applicable Trust Services Criteria, together with an independent service auditor’s opinion. This report is publicly available and can be freely shared.
SOC 2 Type 2 report
The SOC 2 Type 2 report provides detailed information about Lightspeed’s controls relevant to the applicable Trust Services Criteria. It also includes the independent service auditor’s tests of those controls and their operating effectiveness over a specified period.
Because of its sensitive nature, existing customers must request access. Prospective customers must have an NDA in place with Lightspeed.
SOC 2 Bridge Letter
The SOC 2 Bridge Letter is a management-issued document covering the period between the end of the latest SOC 2 reporting period and a specified subsequent date. It communicates whether Lightspeed is aware of any material changes or events that could affect the controls described in the SOC 2 report.
The letter is not an independent audit report and does not extend the SOC 2 auditor’s opinion.
To request specific SOC 2 reports, PCI Attestations of Compliance, or security policy documentation, visit the Resources tab in the Security Trust Center. Access to restricted reports may require appropriate account permissions or a signed NDA.
Downloading PCI and SOC 3 compliance reports
- Navigate to the Security Trust Center.
-
Click the Resources tab.
-
To download all PCI and SOC 3 compliance reports, click Bulk download. To download a specific report, click View next to the report.
-
In the top-right corner, click Download.
To return to the Resources tab, click the X (Exit) in the top-left corner of the screen.
Requesting access to restricted reports
Existing merchants can request access to restricted reports through the Security Trust Center. Every restricted-report request undergoes internal review before access is granted.
- Navigate to the Security Trust Center.
-
At the top-right of the page, click Request access. You can also use the tabs or search bar to locate a specific resource and select Request access.
-
Enter your contact details, including the email address associated with your Lightspeed account. Select a reason for the request from the dropdown menu. The access level and resource are prepopulated.
Submit your request using your official company email address registered with Lightspeed.
- Click Request access.
Every request is subject to internal review. Access is granted only after the request has been reviewed and approved.
If you are a prospective merchant, or if you cannot submit a request or access is not granted, contact Golf Support and provide a list of the specific documents you need. Golf Support can help route your request and explain whether an NDA is required.
Lightspeed continuously invests in security controls, monitoring, and compliance programs to safeguard your data. Learn more on the Lightspeed Trust Center and in the privacy policy.