Enterprise-Grade Protection

    Your Data, Protected.

    At LightDay, your client data is precious. We've built our platform on enterprise-grade infrastructure with multiple layers of security — the same standards used by banks and governments.

    SOC 2 Type 2
    ISO/IEC 27001
    PCI-DSS Compliant
    UK GDPR
    256-bit Encryption
    Security Architecture

    Multiple Layers of Protection

    Security isn't an afterthought — it's built into every layer of our infrastructure.

    Data Encryption

    • Encryption at Rest: All data stored using AES-256 encryption, the same standard used by banks and governments
    • Encryption in Transit: All connections secured with TLS 1.3, ensuring data cannot be intercepted
    • Database Encryption: Database backups are fully encrypted with LUKS encryption

    Infrastructure Security

    • UK/EU Data Centres: Your data is stored in secure, certified data centres within the UK and EU
    • DDoS Protection: Automatic protection against distributed denial-of-service attacks
    • Firewalls & VPCs: Network isolation with enterprise firewalls and virtual private clouds

    Access Controls

    • Role-Based Access: Fine-grained permissions ensure staff only access what they need
    • Secure Authentication: Industry-standard password hashing and session management
    • Audit Logging: Comprehensive logs of all system access and changes

    Backup & Recovery

    • Automated Backups: Daily encrypted backups with point-in-time recovery
    • Disaster Recovery: Geographically distributed backups for business continuity
    • 99.9% Uptime: High-availability infrastructure with redundant systems
    Compliance Standards

    Certified. Audited. Trusted.

    Our infrastructure partners maintain rigorous third-party certifications and undergo regular audits.

    SOC 2 Type 2

    Independent verification of security controls over an extended period

    ISO/IEC 27001:2013

    International standard for information security management

    PCI-DSS Compliant

    Payment Card Industry Data Security Standard for secure payments

    UK GDPR Compliant

    Full compliance with UK data protection regulations

    Payment Security

    All payment processing is handled by Stripe, a globally trusted payment provider. We never store your full card details. Stripe is PCI Level 1 certified — the most stringent level in the payments industry.

    Our Commitment

    • Regular security assessments and penetration testing
    • Continuous monitoring for vulnerabilities and threats
    • Incident response procedures with prompt notification
    • Employee security training and background checks
    • Secure software development lifecycle practices

    Questions About Security?

    We're happy to discuss our security practices in detail. If you have specific requirements, please get in touch.

    [email protected]