Data protection by design
LucenOne provides a foundation designed to support GDPR-compliant processing through minimization, access control, traceability and retention rules. Compliance also depends on the client organization’s processing framework.
TRUST & SECURITY
LucenOne is designed for sensitive information inside an isolated, traceable and governed environment. The essential guarantees should be understandable before a conversation with our team is ever required.
THE ESSENTIAL ANSWERS
Where data is hosted, who can access it, what AI does with it and what it does not do: these are LucenOne’s core guarantees.
LucenOne provides a foundation designed to support GDPR-compliant processing through minimization, access control, traceability and retention rules. Compliance also depends on the client organization’s processing framework.
Client case content is not used to train the models used by LucenOne.
Information from one case is not used to answer inside another. Rights remain bounded by organization, entity, case and role.
LucenOne’s production business-data foundation is hosted within the European Union.
LucenOne is designed and governed around applicable EU AI Act requirements. AI assists; final validation and decision remain human.
AI-assisted results remain connected to supporting elements and important validations are designed to be traceable.
FROM SOURCE TO DECISION
Protection does not begin with AI and does not end after analysis. It follows the source, access rights, context and restitution.
Document, image, audio, video, report or interview.
The source is attached to a case and retains its context.
Security controls during ingestion.
File type, active content, executables, abnormal archives and prompt-injection signals are treated as security risks.
Organization, entity, case and permissions.
Access is enforced server-side and at the data layer, not only in the interface.
Only authorized and necessary context.
No training on client cases, no cross-customer sharing and no reuse of one case to answer another.
Sources, limitations and human validation remain visible.
Analysis assists investigation. Final validation and decision remain human.
Data does not leave its authorized scope simply because an AI capability needs context. The context is constructed and authorized for the requested task.
BOUNDARIES BUILT INTO THE PRODUCT
Sensitive cases must not become invisible raw material for AI.
GDPR & AI GOVERNANCE
LucenOne provides product mechanisms for minimization, isolation, traceability and retention. Complete compliance remains tied to purpose, legal basis, notices, retention choices and the organization’s procedures.
Content is used for the intended LucenOne processing, not to build a general training corpus.
A feature does not receive every available field by default.
Permissions follow scope and need-to-know.
Retention and deletion rules can be aligned with organization requirements.
LucenOne is designed and governed around applicable EU AI Act requirements: transparency, traceability, context control, reviewability and human oversight. The exact regulatory qualification depends on the deployed use case.
Users should be able to identify AI-assisted analysis and proposals.
A useful conclusion remains connected to the elements required to review it.
Qualification, correction, validation and decision remain human responsibilities.
An AI capability works inside task-specific context rather than receiving general tenant access.
SECURITY IN PRACTICE
We publish what a prospect needs to evaluate LucenOne without turning this page into an exploitable architecture diagram.
Incoming sources are treated as untrusted. File types, active content, executables, abnormal archives and malicious signals are part of ingestion controls.
Permissions apply at organization, entity and case level. The interface is not the security boundary.
Technical keys and processing secrets are not exposed to the browser.
An AI capability receives only information authorized and necessary for the requested task.
Important operations, corrections and validations are designed to stay auditable without overwhelming the case with technical logs.
AI results can be reviewed, corrected, completed or rejected by authorized users.
NO TRAINING: WHAT THAT MEANS
An AI capability may need some authorized case content to perform a task. That content does not thereby become shared knowledge or a training corpus.
Only information useful and accessible for the task is selected.
The context is used to produce the expected analysis for this case.
Content is not reused to train models or shared between customers.
FREQUENT QUESTIONS
No. Client case content is not used to train the models used by LucenOne. An AI capability may process context required for an authorized task without authorizing training or reuse for other customers.
No. One case is not used to answer inside another. Authorized aggregate analyses remain separate and do not make one case’s source content visible inside another.
LucenOne’s production business-data foundation is hosted in the European Union.
LucenOne is designed to support GDPR-compliant processing. Complete compliance also depends on the controller’s purpose, legal basis, notices, retention, permissions and procedures.
LucenOne is designed and governed around applicable EU AI Act requirements. Exact qualification depends on the use case and each actor’s regulatory role.
Imported content is treated as untrusted data to analyze, never as system instructions. Prompt-injection signals are among the risks considered in the processing chain.
No. LucenOne can connect, flag, propose or explain. Final validation and decision remain human.
TRUST PACKAGE
For a security questionnaire, DPA, retention requirement, subprocessor review or specific AI-governance need, LucenOne can provide the evidence appropriate to the evaluation context. A meeting is not required to understand the essential principles.