New KPMG Agentic ERP, now available with KPMG in 140+ countries Read the announcement

Data Encryption and Storage

Category
Security
Guide
Admin guides
Reading
5 min read
On this page
  1. 01Encryption Overview
  2. 02Encryption at Rest
  3. 03Encryption in Transit
  4. 04Data in Use
  5. 05Encryption Key Management
  6. 06Regional Data Storage
  7. 07Field-Level Encryption
  8. 08Data Disposal
  9. 09Transparency
  10. 10Related Articles

What is this page about: How Light encrypts and stores your financial data to keep it secure and private. It covers encryption at rest, in transit, and in use, how encryption keys are managed and rotated, where your data is stored, and what happens to it when you delete it. Use it when answering an encryption question in a security review.

On this page

  • Encryption Overview
  • Encryption at Rest
  • Encryption in Transit
  • Data in Use
  • Encryption Key Management
  • Regional Data Storage
  • Field-Level Encryption
  • Data Disposal
  • Transparency
  • Related Articles

Encryption Overview

Light protects all your financial data through encryption. Every piece of information, from bank transactions to invoices to custom configurations, is encrypted using industry-standard algorithms.

Encryption at Rest

Database Encryption

Light encrypts all data stored in its databases:

  • Algorithm: AES-256 encryption
  • Scope: All financial records, company data, user information, and audit logs
  • Key Management: Encryption keys are stored separately from encrypted data in a dedicated key management service
  • Automatic: Light encrypts your data without any configuration from you

All data in Light's databases is unreadable without the correct encryption key.

Storage Encryption

Beyond database encryption, Light adds additional protection:

  • File Storage: Documents (invoices, receipts, etc.) uploaded to Light are encrypted before storage
  • Backup Encryption: Database and file backups are encrypted immediately upon creation
  • Archive Encryption: Older data moved to long-term archives remains encrypted

Backup Security

Light maintains encrypted backups for disaster recovery:

  • Frequency: A full backup daily, with continuous point-in-time recovery for databases
  • Retention: Database backups are retained for 30 days. Daily backup copies are kept for 14 days, and weekly and monthly copies for up to 365 days
  • Encryption: All backups are encrypted with AES-256
  • Testing: Recovery procedures are tested regularly to ensure backups are reliable
  • Location: Backups are stored across multiple availability zones, with encrypted copies replicated to a second EU region for disaster recovery

Good to know: Even if someone gained access to Light's backup systems, the encrypted data would be useless without the encryption keys.

Encryption in Transit

HTTPS/TLS Encryption

All communication between your browser or mobile app and Light uses HTTPS:

  • Protocol: TLS 1.2 or higher
  • Certificates: Valid SSL/TLS certificates signed by trusted certificate authorities
  • Ciphers: Only strong encryption ciphers are enabled; weak ones are disabled
  • Perfect Forward Secrecy: Even if an encryption key is compromised in the future, historical communication remains secure

API Encryption

Light's APIs use encrypted communication:

  • Protocol: HTTPS/TLS for all API requests
  • Authentication: API keys or OAuth 2.0 tokens, always transmitted over TLS
  • Validation: Requests are validated to prevent tampering
  • Logging: API requests are logged with sensitive headers and query parameters redacted; credentials are never written to logs

Integration Security

When Light communicates with external services (banks, payment processors, CRM systems):

  • Encrypted connections: Traffic between Light and the external service is encrypted in transit
  • Validation: Outbound connections use TLS with full certificate validation, and inbound webhooks are verified with signatures before processing
  • Audit Trail: All integration communication is logged and audited

Data in Use

Application-Level Encryption

Even while data is being processed, sensitive information remains encrypted:

  • Sensitive Fields: Selected fields, including card 3-D Secure credentials, are encrypted at the application level on top of storage-layer encryption
  • Processing: The application only decrypts data when necessary to perform operations
  • No Logging: Sensitive data is never logged in plaintext

Encryption Key Management

Key Rotation

Light rotates encryption keys regularly:

  • Frequency: KMS-managed keys, which encrypt your data at rest, rotate annually. Application-level field keys are rotated as a manual operational task rather than on a fixed schedule
  • New Keys: Keys used for new data are different from those used for older data
  • Seamless: Keys can be rotated without downtime and without affecting your access

Key Access Control

Encryption keys are protected:

  • Limited Access: Keys are managed in AWS KMS. Access is restricted to the encryption service and a small number of privileged administrators
  • Separation: Keys are stored separately from encrypted data
  • Monitoring: Every use of a key is logged and monitored

Backup Key Protection

Keys used for backup recovery:

  • Separate Protection: Backup encryption keys are kept in separate secure storage
  • Tested: Recovery procedures are regularly tested to ensure keys work when needed
  • Long-Term: Keys are maintained for as long as the backups they protect, up to 365 days

Regional Data Storage

Light stores your data in the European Union:

  • Data Location: All customer data is hosted on AWS infrastructure in the EU, with Ireland (eu-west-1) as the primary region
  • Replication: Failover copies are kept across multiple availability zones, and encrypted backup copies replicate to Frankfurt (eu-central-1) for disaster recovery. Both regions are in the EU
  • Compliance: EU data storage supports GDPR requirements

Field-Level Encryption

Certain sensitive fields receive additional encryption layers:

  • Card Security Data: Card 3-D Secure credentials are encrypted with versioned keys, so keys can be rotated without downtime while older data stays readable

Data Disposal

When you delete data or accounts, Light securely disposes of it:

  • Immediate Deletion: Light deletes the data from live systems straight away
  • Cascade Deletion: Related data is deleted alongside it
  • Backups: Encrypted copies remain in backups until those backups expire, which takes up to 365 days
  • Verification: Once the last backup holding it has expired, the data is no longer recoverable

Tip: Light maintains an audit log of all deletions for 7 years. This helps verify that data has been properly disposed of.

Transparency

Light is transparent about encryption:

  • Security Audit Reports: Third-party SOC 2 audits cover Light's security controls
  • Documentation: Full technical documentation of encryption methods is available under NDA
  • Testing: Regular penetration testing verifies encryption cannot be bypassed

Was this article helpful?