Purpose and Scope
This policy describes the standards LightSpeed VT uses to protect its SaaS application, the infrastructure it runs on, and the customer data it stores. It applies to all Amazon Web Services (AWS) cloud resources operated by LightSpeed VT for the LightSpeed VT SaaS application, and to all personnel with access to them.
LightSpeed VT's security program is aligned with the CIS Critical Security Controls (v8) published by the Center for Internet Security, and operating systems are hardened in accordance with CIS Benchmarks (cisecurity.org).
Policy review: This policy is reviewed at least annually and whenever there is a material change to our infrastructure. Last reviewed: October 5, 2026
Hosting, Data Location, and Responsibilities
LightSpeed VT runs 100% of its SaaS application infrastructure on Amazon Web Services, including client-facing portals, video content, and the main application and database.
- Data location: All customer data is hosted in U.S.-based AWS regions. Customer data is not stored outside the United States.
- Network isolation: Production servers run inside an AWS Virtual Private Cloud (VPC). Traffic between application subnets is controlled by security groups and network access-control lists.
- Shared responsibility: AWS is responsible for the physical security of its data centers and the underlying hardware. LightSpeed VT is responsible for configuring, maintaining, patching, and securing the virtual servers, databases, and application it runs on AWS.
Configuration and Hardening
- Operating systems are installed and configured in accordance with CIS Benchmarks.
- Services and applications that are not required are disabled.
- Standard security principles of least required access are used for all server and application functions.
- Administrative accounts are not used when a non-privileged account will do.
Access Control
- Access to servers and AWS resources is restricted to authorized LightSpeed VT personnel with a business need.
- Access is protected through AWS Identity and Access Management (IAM), VPN connections, and encrypted SSH or RDP connections.
- Multi-factor authentication (MFA) is required for AWS console access and all privileged accounts.
- Privileged access is performed only over encrypted channels.
- Access rights are reviewed at least annually, and access is removed promptly when personnel change roles or leave the company.
Encryption
- In transit: All communication between users' browsers and the LightSpeed VT application is encrypted using TLS 1.2 or higher.
- At rest: Customer data stored in databases, storage volumes, and backups is encrypted at rest using AES-256 through AWS-managed encryption.
- Passwords: User passwords are stored only as salted, one-way hashes and are never stored in plain text.
Vulnerability and Patch Management
- Security patches are applied to servers and systems on a regular schedule. Critical security patches are applied within 14 days of release, unless doing so would cause a service disruption, in which case compensating controls are applied until the patch is installed.
- Systems are scanned for vulnerabilities at least quarterly, and findings are remediated based on severity.
- Application changes go through LightSpeed VT's software quality assurance process before release (see Software Quality Assurance Policies).
Logging and Monitoring
- Security-related events on critical systems are logged, and audit logs are retained for at least 90 days.
- Monitoring agents alert systems administration to application, network, or security irregularities.
- Security-related events are reviewed by systems administration and escalated to IT management, with corrective action taken as needed. These events include port-scan attacks, denial-of-service (DDoS) attacks, evidence of unauthorized access to privileged accounts, and anomalous activity not related to normal application use.
Backups
- Production data is backed up automatically each day using AWS automated database snapshots, with backups retained for at least 30 days.
- Backups are encrypted and stored within U.S.-based AWS regions.
- See Data & File Back-Up Procedures and Disaster Avoidance & Recovery for details.
Incident Response
LightSpeed VT maintains a written incident response plan for identifying, containing, investigating, and recovering from security incidents. If LightSpeed VT becomes aware of a security incident involving customer personal data, we will notify the affected customer without undue delay, and in any event within 72 hours, as described in Security of Data & Content.
Personnel Security
- All personnel with access to customer data sign confidentiality agreements.
- Personnel complete security awareness training at onboarding and at least annually.
- LightSpeed VT's engineering, infrastructure, database, and network administration staff are in-house.
Application Security Features
- Two-factor authentication (2FA) is available for user accounts.
- Password requirements are enforced as described in the Application Password Policy.
- Inactive sessions time out automatically and can be customized per account (see Custom Session Time-out).
- Concurrent sign-ins with the same username are restricted (see Password Sharing).
Security Assessments and Compliance
- LightSpeed VT conducts a security assessment of its infrastructure and controls at least annually, and after any confirmed security incident.
- A summary of the most recent assessment is available to customers upon request under a confidentiality agreement.
- AWS maintains independent certifications and audit reports for its infrastructure, including SOC 2 and ISO 27001, available through AWS Compliance Programs and AWS Artifact.
Related Policies
Security of Data & Content · Data & File Back-Up Procedures · Disaster Avoidance & Recovery · Application Password Policy · Software Quality Assurance Policies · General Data Retention · Privacy Notice