name: Lightspeed Commerce Trust Center generated: '2026-08-27' method: searched source: https://trust.lightspeedhq.com/ and https://www.lightspeedhq.com/security/ trust_center: url: https://trust.lightspeedhq.com/ http_status: 200 probed: '2026-08-27' platform: Vanta Trust Center machine_readable: false note: >- The trust center itself is a client-rendered Vanta app — the shell served to a crawler is 7KB of JavaScript with the title "Lightspeed Trust Center" and no certification names in the HTML. The named certifications below therefore come from the statically-rendered https://www.lightspeedhq.com/security/ page, which is where they are actually readable. certifications: - name: PCI DSS status: attested detail: >- Lightspeed states it does not store, process or transmit cardholder data; payment transactions are handled by PCI-compliant providers. Attestations of Compliance (AoC) are published per product line, including an E-Series PCI AoC and a U-Series PCI AoC. - name: SOC 2 status: audited detail: Certain Lightspeed products are audited yearly for SOC 2 (security, availability, processing integrity, confidentiality, privacy). - name: SOC 3 status: published detail: >- Public SOC 3 reports are linked for NuORDER by Lightspeed and for Lightspeed Commerce covering R-Series, X-Series, C-Series, E-Series, K-Series, L-Series, O-Series, U-Series, Golf and Payments. - name: GDPR status: claimed detail: Named among the frameworks Lightspeed and its infrastructure providers maintain. subprocessor_certifications: note: >- Lightspeed states its outsourced infrastructure providers maintain SOC 2 Type II, ISO 27001, PCI DSS, GDPR, FIPS 140-2 and NIST framework certifications. These are the providers' certifications, not Lightspeed's own, and are recorded separately for that reason. regional_variants: - https://www.lightspeedhq.com/security/ - https://www.lightspeedhq.com/uk/security/ - https://www.lightspeedhq.com/au/security/