Hi. How can we help?

Accessing Lightspeed's security compliance reports

The Security Trust Center serves as a central hub for compliance reports, security policies, and other useful resources, providing transparency and access to essential security information. This article provides an overview of Lightspeed's compliance reports across Retail, Hospitality, and Golf product Series.

Security Trust Center landing page.

You can click the tabs at the top of the Security Trust Center for more information on:

  • Resources: View and download compliance reports and redacted policies:
    • PCI and SOC3 compliance reports (access requests not required)
    • Redacted information security policies, SOC2 Type 2 compliance reports, penetration testing attestations, PCI Roles and Responsibilities Matrix (access requests required)
  • Controls: View Lightspeed’s organizational security and privacy controls.
  • Subprocessors: More information on the subprocessors engaged by Lightspeed as necessary to process customer data and provide Lightspeed Services.
  • FAQ: Additional information on the Trust Center and bug bounty program.

Some documents within the Resources section are access-restricted and not publicly viewable or downloadable. Access to these documents is reserved for existing merchants or for prospective merchants who have a valid Non-Disclosure Agreement (NDA) in place with Lightspeed.

Understanding Payment Card Industry (PCI) reports

The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard designed to protect payment account data. It applies to entities that store, process, or transmit cardholder data or sensitive authentication data, as well as entities that could impact the security of the cardholder data environment.

The standard was developed to enhance the security of payment account data by establishing consistent technical and operational security requirements. PCI reports document an organization’s PCI DSS assessment results and its compliance status against the requirements maintained by the PCI Security Standards Council.

Available reports

PCI Attestation of Compliance (AoC)

The AoC is an official document confirming the results of Lightspeed's annual PCI DSS compliance assessment. Lightspeed issues an updated AoC for each applicable product platform following the completion of its annual assessment. These documents are publicly available. You can access these documents via the Security Trust Center.

Understanding Service Organization Control (SOC 2) reports

Service Organization Control (SOC 2) reports evaluate an organization’s controls relevant to security, confidentiality, privacy, processing integrity, and availability, based on the Trust Services Criteria applicable to the assessment. The Trust Services Criteria are established and maintained by the American Institute of Certified Public Accountants (AICPA).

Available reports

SOC 3 report

The SOC 3 report provides a high-level, general-use summary of Lightspeed's controls relevant to the applicable Trust Services Criteria, together with an independent service auditor’s opinion. This report is publicly available and can be freely shared.

SOC 2 Type 2 reporte

The SOC 2 Type 2 report provides detailed information about Lightspeed’s controls relevant to the applicable Trust Services Criteria, as well as the independent service auditor’s tests of those controls and their operating effectiveness over a specified period. Due to its sensitive nature, existing customers must request to access it, while non-customers are required to enter into an NDA.

SOC 2 Bridge Letter

The SOC 2 Bridge Letter is a management-issued document covering the period between the end of the latest SOC 2 reporting period and a specified subsequent date. It communicates whether Lightspeed is aware of any material changes or events that could affect the controls described in the SOC 2 report. The letter is not an independent audit report and does not extend the SOC 2 auditor’s opinion.

To request or download specific SOC 2 reports, PCI Attestations of Compliance, or security policy documentation, visit the Resources tab in the Security Trust Center. Access to confidential reports may require appropriate account permissions or a signed NDA.

Downloading PCI and SOC3 compliance reports

  1. Navigate to the Security Trust Center.
  2. Click the Resources tab.

    Security Trust Center with Resources tab highlighted.

  3. To download all PCI and SOC3 compliance reports, click Bulk download, or click View next to a specific report.

    Security Trust Center Resources tab with Bulk download button highlighted.

  4. In the top right corner, click Download.

    PCI AOC page with Download button highlighted.

To return to the Resources tab, click the X (Exit) at the top-left of the screen.

Requesting access to restricted reports

Existing Lightspeed merchants can self-serve access to restricted reports directly through the Security Trust Center:

  1. Navigate to the Security Trust Center.
  2. At the top right of the page, click Request access or use the tabs or search bar to locate a specific resource Request access.

    Security Trust Center reports page with Request access button highlighted.

  3. Fill out your contact details, including the email address associated with your Lightspeed account, and select a reason for the request from the dropdown menu. The access level and resource will be prepopulated.

    You must submit your request using your official company email address registered with Lightspeed.

    Security Trust Center with Request access form pop-up.

  4. Click Request access.

The system will validate your account and grant instant access to the requested reports.

If access is not granted, for example if your current email differs from the primary contact email in your account, or you are not a Lightspeed merchant, contact Retail Support and provide a list of the specific documents required. All requests are subject to an internal validation process before access can be granted.

Lightspeed is continuously investing in security controls, monitoring, and compliance programs to safeguard your data. Learn more on the Lightspeed Trust Center and in the privacy policy.

Was this article helpful?