Legal
LightEDR uses a limited number of third-party service providers ("sub-processors") in the delivery of its platform. This page lists them, what data each receives, and their location. We notify customers at least 30 days before adding a new sub-processor that handles Customer Data.
These are always active for every LightEDR tenant.
| Sub-processor | Purpose | Data received | Location | Transfer mechanism |
|---|---|---|---|---|
| Hostinger | Hosting infrastructure - your tenant data, detection engine, and dashboard are hosted on servers we operate via Hostinger. | All Customer Data at rest on the hosted servers | UK / EU | UK GDPR adequacy / EU Standard Contractual Clauses |
| Hostinger | Transactional email - verification links, alert digest emails, billing receipts. | Recipient email address, message content | UK / EU | UK GDPR adequacy / EU Standard Contractual Clauses |
| Stripe, Inc. | Payment processing for paid plans. | Billing email, payment token, invoice history. Card numbers are never seen by LightEDR. | United States | EU-US Data Privacy Framework / UK adequacy regulations |
These processors have access to visitor behaviour on lightedr.com only. They have no access to any Customer Data stored in the platform.
| Sub-processor | Purpose | Data received | Location | Transfer mechanism |
|---|---|---|---|---|
| Microsoft Clarity | Anonymised session analytics on the lightedr.com marketing website. Only loaded after cookie consent is given. | Anonymised page interaction events, session recordings. No Customer EDR data. | United States | EU-US Data Privacy Framework / UK adequacy |
These sub-processors are only active if a tenant administrator explicitly enables and configures the integration from the dashboard. No data is sent to them unless the integration is both configured and enabled. The data transmitted is security telemetry (IP addresses, file hashes, alert content) - not personal data in the traditional sense, but it does constitute Customer Data under your agreement with LightEDR.
| Sub-processor | Purpose | Data sent when enabled | Location |
|---|---|---|---|
| AbuseIPDB | IP address reputation lookups. Enriches alerts with known malicious IP context. | IP addresses observed in network connection events | United States |
| VirusTotal (Google LLC) | File hash analysis against 70+ AV engines. Enriches alerts containing file hashes. | SHA256, SHA1, and MD5 file hashes from endpoint events | United States |
| GreyNoise Intelligence | Classifies internet scanner and noise IPs to reduce false-positive alert volume. | IP addresses observed in network connection events | United States |
When an LLM integration is enabled, alert content (process names, command-line arguments, IP addresses, file paths, and detection rule context) is sent to the configured provider to generate triage explanations and suggestions. Only one LLM provider can be active at a time. Ollama is fully local and sends no data externally.
| Sub-processor | Purpose | Data sent when enabled | Location |
|---|---|---|---|
| Anthropic, PBC (Claude) | LLM-native alert triage, incident clustering, natural language threat hunting. | Alert content: process names, commands, IPs, file paths, rule context | United States |
| OpenAI, LLC | LLM-native alert triage. | Alert content: process names, commands, IPs, file paths, rule context | United States |
| Microsoft Azure OpenAI | LLM-native triage via Azure-hosted OpenAI models. Offers EU data-residency options depending on the Azure region configured. | Alert content: process names, commands, IPs, file paths, rule context | Customer-configured (EU option available) |
| Google DeepMind (Gemini) | LLM-native alert triage. Suited to large alert volumes owing to long-context capability. | Alert content: process names, commands, IPs, file paths, rule context | United States |
| Ollama (self-hosted) | Fully local LLM inference - air-gapped, no data leaves the customer's network. | None - processed locally on customer infrastructure | Customer's own infrastructure |
| Sub-processor | Purpose | Data sent when enabled | Location |
|---|---|---|---|
| Customer-configured webhook endpoint | HTTP POST alert notifications to a URL of the tenant's choosing (e.g. a SIEM, ticketing system, or Slack webhook). | Alert content above the configured severity threshold, HMAC-signed if configured. Sent to the customer's own endpoint - LightEDR does not operate this destination. | Customer-defined |
We will give at least 30 days' notice by email before adding a new sub-processor that handles Customer Data. The current version of this list is always available at lightedr.com/legal/sub-processors/.
To object to the addition of a new sub-processor, contact legal@lightedr.com within the 30-day notice period. Where objection cannot be resolved, you may terminate your subscription in accordance with the Terms of Service §13.