Encryption and key custody
Protect data in transit and at rest. HYOK for LLM APIs where applicable, so key custody stays with you.
Full self-hosted deployment. SSO, SCIM, RBAC, and audit trails under your control. Send this page before your first internal meeting.
Data residency
Prompts, documents, agent outputs, and audit logs remain inside the infrastructure you control. Orchestration always runs self-hosted. Inference can stay on-prem or in your VPC, or use Lunnoa-offered or customer-chosen LLM endpoints when you configure them.
Agents, workflows, and the control plane run in your environment. Lunnoa GmbH has no access to customer data or agent runs after deployment.
Bring your own models, host open-source models yourself, or use Lunnoa-offered model access. Each option has different residency implications, and you choose which path applies.
Controls
Enterprise controls ship with the platform. Deep product detail lives on Security & governance.
Protect data in transit and at rest. HYOK for LLM APIs where applicable, so key custody stays with you.
Centralised identity with just-in-time provisioning and automated lifecycle. Role-based access for builders and reviewers.
Immutable trails for who triggered a run, what data was touched, and what actions followed. Built for “why did it do that?” reviews.
Human-in-the-loop gates, policy bindings, and approval paths so business users build while IT sets the guardrails.
Certification
No “ready” theatre. Status you can put in a questionnaire today.
Self-hosted posture, data sovereignty by default, and auditability designed for accountability requirements.
Labelled for transparent, responsible AI development and operations in Switzerland.
Read the Swiss Made pageIn progress toward Type II. We will publish the report when it is complete, not before.
Operating artefacts
Structural answers now. Formal schedules and PDFs follow in the brief when you need them.
For the self-hosted platform runtime, Lunnoa GmbH is not in the customer data path. When you use Lunnoa-offered LLM access or third-party model APIs, those providers (and their chains) are in scope and disclosed in the security brief on request.
Report suspected vulnerabilities through our contact channel. We acknowledge responsible disclosure and will coordinate a fix before public detail is shared.
A short brief your champion can forward to IT. Request it on a call until the PDF is published.
Request the security one-pagerFAQ
Straight answers for questionnaire owners and architecture reviews.
Orchestration, logs, and platform data stay in your environment by default. Inference only leaves if you configure an external or Lunnoa-offered LLM endpoint. You control that split.
Yes. You can bring your own models, host open-source models yourself, or use Lunnoa-offered model access. We will document the residency and sub-processor implications for the path you choose in the security brief.
Lunnoa integrates with enterprise identity providers for SSO and SCIM lifecycle management, with RBAC for who can build, approve, and review. Detail and screenshots are on the Security & governance platform page.
Yes. Runs are attributable: who triggered them, what was processed, and what actions were taken. Export and retention are configured for your environment and review process.
SOC 2 Type II is targeted for Q1 2027. We do not claim “SOC 2 ready.” GDPR-oriented design and Swiss Made Software +AI apply today.
Because the platform runs in your infrastructure, your agents and workflows keep running on systems you control. Continuity, escrow, and exit terms are covered in the commercial and security brief.
Walk through residency, controls, and certification status with your IT and compliance stakeholders.