LightSite AI Security & Trust

This page summarizes the security, privacy and data-handling practices of Lightsite Ltd., operating as Lightsite AI. It is general information and does not modify the Terms and Conditions, the Data Processing Addendum, or any Order Form. Last updated 6 August 2026.

Platform Architecture

LightSite AI runs as a parallel AI-search infrastructure and analytics layer. It deploys machine-readable resources such as AI sitemaps, structured endpoints, JSON-LD, agent manifests and Skills API endpoints, and measures how AI crawlers and AI-referred visitors interact with a customer's site. Normal page traffic is not proxied through LightSite AI, so a LightSite outage does not take the customer's website down. The standard integration is a lightweight JavaScript snippet plus LightSite-specific redirects or discovery rules, and requires no database credentials or privileged access to internal systems.

Data Handled by the Website Integration

The integration processes publicly available website content and technical event data about AI crawler activity, AI extraction, Skills API usage and AI-referred visits. It is designed to operate without cookies, local storage or browser fingerprinting, and not to collect visitor names, email addresses, credentials, payment data or form contents. Account and administrative information for authenticated platform users is handled as described in the Privacy Policy.

Data Residency and Infrastructure

The primary production database is hosted in Frankfurt, Germany on AWS infrastructure. Managed cloud providers support database, authentication, hosting, communications and AI processing. A current sub-processor list is available at support@lightsite.ai.

Encryption and Access Controls

Controls include encryption in transit using TLS 1.2 or higher and encryption at rest, organization-scoped access controls and tenant isolation, least-privilege internal administrative access, managed secrets and credential controls, multi-factor authentication and Microsoft Entra ID SSO support, and logging and monitoring of authentication, application and system activity.

Security Testing and Vulnerability Management

LightSite AI uses managed infrastructure, dependency and code security scanning, vulnerability management, and controlled production deployment practices. Independent security testing and external security or architecture reviews are performed as appropriate, and enterprise security documentation is available on request.

AI and Model Training

LightSite AI does not use Customer Data to train general-purpose AI models and does not provide Customer Data to third-party AI providers for model training. Publicly available information and anonymized, aggregated, de-identified or derived data that does not identify a customer, individual or confidential information may be used to develop, test, evaluate and improve the Services.

Availability and Customer Impact

Because the LightSite layer sits alongside the customer's website rather than in front of it, machine-readable endpoints and analytics may be unavailable during an outage while the customer's primary website remains available. Availability and support commitments are in the Service Level Agreement.

Enterprise Security Reviews

For enterprise procurement, LightSite AI can provide a detailed Security Overview, respond to security questionnaires and supply supporting materials. Customer-specific commitments must be agreed in the applicable Order Form. Enterprise teams can also review AI search infrastructure for enterprises.

Contact

Security questions and documentation requests: support@lightsite.ai. See also the Privacy Policy, Terms and Conditions and Data Processing Addendum.