LightEDR
Product
PricingCompanyBlogDocs
Sign inGet started

Legal

Sub-processor List

Last updated: 25 May 2026

LightEDR uses a limited number of third-party service providers ("sub-processors") in the delivery of its platform. This page lists them, what data each receives, and their location. We notify customers at least 30 days before adding a new sub-processor that handles Customer Data.

Core platform sub-processors

These are always active for every LightEDR tenant.

Sub-processorPurposeData receivedLocationTransfer mechanism
HostingerHosting infrastructure - your tenant data, detection engine, and dashboard are hosted on servers we operate via Hostinger.All Customer Data at rest on the hosted serversUK / EUUK GDPR adequacy / EU Standard Contractual Clauses
HostingerTransactional email - verification links, alert digest emails, billing receipts.Recipient email address, message contentUK / EUUK GDPR adequacy / EU Standard Contractual Clauses
Stripe, Inc.Payment processing for paid plans.Billing email, payment token, invoice history. Card numbers are never seen by LightEDR.United StatesEU-US Data Privacy Framework / UK adequacy regulations

Marketing website only

These processors have access to visitor behaviour on lightedr.com only. They have no access to any Customer Data stored in the platform.

Sub-processorPurposeData receivedLocationTransfer mechanism
Microsoft ClarityAnonymised session analytics on the lightedr.com marketing website. Only loaded after cookie consent is given.Anonymised page interaction events, session recordings. No Customer EDR data.United StatesEU-US Data Privacy Framework / UK adequacy

Optional integrations

These sub-processors are only active if a tenant administrator explicitly enables and configures the integration from the dashboard. No data is sent to them unless the integration is both configured and enabled. The data transmitted is security telemetry (IP addresses, file hashes, alert content) - not personal data in the traditional sense, but it does constitute Customer Data under your agreement with LightEDR.

Threat intelligence

Sub-processorPurposeData sent when enabledLocation
AbuseIPDBIP address reputation lookups. Enriches alerts with known malicious IP context.IP addresses observed in network connection eventsUnited States
VirusTotal (Google LLC)File hash analysis against 70+ AV engines. Enriches alerts containing file hashes.SHA256, SHA1, and MD5 file hashes from endpoint eventsUnited States
GreyNoise IntelligenceClassifies internet scanner and noise IPs to reduce false-positive alert volume.IP addresses observed in network connection eventsUnited States

LLM / AI triage

When an LLM integration is enabled, alert content (process names, command-line arguments, IP addresses, file paths, and detection rule context) is sent to the configured provider to generate triage explanations and suggestions. Only one LLM provider can be active at a time. Ollama is fully local and sends no data externally.

Sub-processorPurposeData sent when enabledLocation
Anthropic, PBC (Claude)LLM-native alert triage, incident clustering, natural language threat hunting.Alert content: process names, commands, IPs, file paths, rule contextUnited States
OpenAI, LLCLLM-native alert triage.Alert content: process names, commands, IPs, file paths, rule contextUnited States
Microsoft Azure OpenAILLM-native triage via Azure-hosted OpenAI models. Offers EU data-residency options depending on the Azure region configured.Alert content: process names, commands, IPs, file paths, rule contextCustomer-configured (EU option available)
Google DeepMind (Gemini)LLM-native alert triage. Suited to large alert volumes owing to long-context capability.Alert content: process names, commands, IPs, file paths, rule contextUnited States
Ollama (self-hosted)Fully local LLM inference - air-gapped, no data leaves the customer's network.None - processed locally on customer infrastructureCustomer's own infrastructure

Notifications

Sub-processorPurposeData sent when enabledLocation
Customer-configured webhook endpointHTTP POST alert notifications to a URL of the tenant's choosing (e.g. a SIEM, ticketing system, or Slack webhook).Alert content above the configured severity threshold, HMAC-signed if configured. Sent to the customer's own endpoint - LightEDR does not operate this destination.Customer-defined

Changes to this list

We will give at least 30 days' notice by email before adding a new sub-processor that handles Customer Data. The current version of this list is always available at lightedr.com/legal/sub-processors/.

To object to the addition of a new sub-processor, contact legal@lightedr.com within the 30-day notice period. Where objection cannot be resolved, you may terminate your subscription in accordance with the Terms of Service §13.

LightEDR

Lightweight endpoint detection & response, built for SOC teams and security partners.

Product

  • Overview
  • AI & Agents
  • Aggregators
  • Zero Trust EDR
  • For SOC Teams
  • For MSSPs
  • Pricing

Compare

  • vs CrowdStrike
  • vs SentinelOne
  • vs Huntress
  • vs Defender

Blog

  • All posts

Company

  • About
  • Security
  • Contact
  • Partner enquiries
© 2026 LightEDR Ltd
Terms of ServicePrivacy PolicySub-processorslegal@lightedr.com

We use analytics cookies (Microsoft Clarity) to understand how visitors use this site. The platform itself sets no third-party cookies.

We use analytics cookies to understand site usage.