We're building the EDR we wanted to run.
LightEDR is built by a small team of former SOC analysts, detection engineers, and infrastructure people who got tired of wrestling with legacy platforms.
Our take.
The EDR market hit a local maximum. Agents got heavier, consoles got noisier, feature checklists got longer, and the analysts who actually use these tools got buried in alerts that don't mean anything.
We think there's a better path - one where the agent is genuinely lightweight, the ruleset is curated instead of exhaustive, and the pricing is knowable without a sales call.
LightEDR is that path, for SOC teams and the security partners who serve them.
Principles.
- Signal beats coverage.
We'd rather ship 400 great rules than 40,000 noisy ones.
- Analysts are users, not targets.
Product decisions route through people who do the work.
- No kernel modules, no surprise outages.
eBPF on Linux. ESF on macOS. Minimal footprint everywhere.
- Transparent pricing, always.
If it's on the pricing page, it's what you'll pay.
We take this seriously.
We're a small team, not an enterprise compliance machine - but we're not cutting corners either.
SOC 2 Type II
In progress. We're working through the audit now. Report available to prospective customers who ask.
Responsible disclosure
Security issues go to security@lightedr.com. We respond fast and credit researchers publicly.
Zero Trust by default
mTLS on every connection, private keys never leave endpoints, hash-chained audit log. Security is in the product, not a policy doc.
Single-region for now
UK (Manchester), with additional regions on the roadmap. Multi-region self-hosting is available today via the Helm chart.
Talk to a human.
Questions, RFPs, partnerships, or press - we actually respond.