Lightspeed Commerce · Trust Center

Lightspeed Trust Center

Trust center

Lightspeed Commerce maintains a public trust center documenting PCI DSS, SOC 2, SOC 3, and GDPR compliance.

CommercePoint-of-SaleRetailRestaurantInventoryLoyaltyPaymentsE-CommerceOmnichannel
Trust center:

Certifications & Compliance

PCI DSSSOC 2SOC 3GDPR

Source

Trust Center

Raw ↑
name: Lightspeed Commerce Trust Center
generated: '2026-08-27'
method: searched
source: https://trust.lightspeedhq.com/ and https://www.lightspeedhq.com/security/
trust_center:
  url: https://trust.lightspeedhq.com/
  http_status: 200
  probed: '2026-08-27'
  platform: Vanta Trust Center
  machine_readable: false
  note: >-
    The trust center itself is a client-rendered Vanta app — the shell served to a crawler is 7KB of
    JavaScript with the title "Lightspeed Trust Center" and no certification names in the HTML. The
    named certifications below therefore come from the statically-rendered
    https://www.lightspeedhq.com/security/ page, which is where they are actually readable.
certifications:
- name: PCI DSS
  status: attested
  detail: >-
    Lightspeed states it does not store, process or transmit cardholder data; payment transactions are
    handled by PCI-compliant providers. Attestations of Compliance (AoC) are published per product
    line, including an E-Series PCI AoC and a U-Series PCI AoC.
- name: SOC 2
  status: audited
  detail: Certain Lightspeed products are audited yearly for SOC 2 (security, availability, processing integrity, confidentiality, privacy).
- name: SOC 3
  status: published
  detail: >-
    Public SOC 3 reports are linked for NuORDER by Lightspeed and for Lightspeed Commerce covering
    R-Series, X-Series, C-Series, E-Series, K-Series, L-Series, O-Series, U-Series, Golf and Payments.
- name: GDPR
  status: claimed
  detail: Named among the frameworks Lightspeed and its infrastructure providers maintain.
subprocessor_certifications:
  note: >-
    Lightspeed states its outsourced infrastructure providers maintain SOC 2 Type II, ISO 27001,
    PCI DSS, GDPR, FIPS 140-2 and NIST framework certifications. These are the providers' certifications,
    not Lightspeed's own, and are recorded separately for that reason.
regional_variants:
- https://www.lightspeedhq.com/security/
- https://www.lightspeedhq.com/uk/security/
- https://www.lightspeedhq.com/au/security/

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lightspeed-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.