TRUST & SECURITY

Your cases stay your cases.

LucenOne is designed for sensitive information inside an isolated, traceable and governed environment. The essential guarantees should be understandable before a conversation with our team is ever required.

Production business data hosted in the EUNo training on client case contentOrganization · entity · case isolationHuman validation and final decision
TRUST BOUNDARYAUTHORIZED CASE
LucenOneAUTHORIZED CASE
AccessDataAI contextAudit trail
No client-data trainingNo case-to-case leakage
GDPREU AI ACTEU HOSTINGISOLATIONTRACEABILITY

THE ESSENTIAL ANSWERS

Security should not require a meeting to be understood.

Where data is hosted, who can access it, what AI does with it and what it does not do: these are LucenOne’s core guarantees.

GDPR

Data protection by design

LucenOne provides a foundation designed to support GDPR-compliant processing through minimization, access control, traceability and retention rules. Compliance also depends on the client organization’s processing framework.

AI

No training on your cases

Client case content is not used to train the models used by LucenOne.

ISOLATION

Every case stays inside its scope

Information from one case is not used to answer inside another. Rights remain bounded by organization, entity, case and role.

HOSTING

Production business data in the EU

LucenOne’s production business-data foundation is hosted within the European Union.

EU AI ACT

Assistive AI under human control

LucenOne is designed and governed around applicable EU AI Act requirements. AI assists; final validation and decision remain human.

TRACEABILITY

Important operations remain auditable

AI-assisted results remain connected to supporting elements and important validations are designed to be traceable.

FROM SOURCE TO DECISION

Data stays inside a controlled scope at every step.

Protection does not begin with AI and does not end after analysis. It follows the source, access rights, context and restitution.

01

Intake

Document, image, audio, video, report or interview.

The source is attached to a case and retains its context.

02

Protection

Security controls during ingestion.

File type, active content, executables, abnormal archives and prompt-injection signals are treated as security risks.

03

Authorized scope

Organization, entity, case and permissions.

Access is enforced server-side and at the data layer, not only in the interface.

04

AI processing

Only authorized and necessary context.

No training on client cases, no cross-customer sharing and no reuse of one case to answer another.

05

Restitution

Sources, limitations and human validation remain visible.

Analysis assists investigation. Final validation and decision remain human.

Data does not leave its authorized scope simply because an AI capability needs context. The context is constructed and authorized for the requested task.

BOUNDARIES BUILT INTO THE PRODUCT

What LucenOne does not do.

Sensitive cases must not become invisible raw material for AI.

Train models with client case content.
Mix several customers’ case data to produce an answer.
Reuse one case to answer inside another case.
Let an attachment become a system instruction for AI.
Give AI authority to make the final decision alone.
Open data access merely because an AI feature requests it.

GDPR & AI GOVERNANCE

Compliance principles must become operational choices.

GDPR: data protection by design

LucenOne provides product mechanisms for minimization, isolation, traceability and retention. Complete compliance remains tied to purpose, legal basis, notices, retention choices and the organization’s procedures.

Purpose

Content is used for the intended LucenOne processing, not to build a general training corpus.

Minimization

A feature does not receive every available field by default.

Access

Permissions follow scope and need-to-know.

Retention

Retention and deletion rules can be aligned with organization requirements.

EU AI Act: assistive, governed and supervised AI

LucenOne is designed and governed around applicable EU AI Act requirements: transparency, traceability, context control, reviewability and human oversight. The exact regulatory qualification depends on the deployed use case.

Transparency

Users should be able to identify AI-assisted analysis and proposals.

Sources

A useful conclusion remains connected to the elements required to review it.

Human oversight

Qualification, correction, validation and decision remain human responsibilities.

Controlled context

An AI capability works inside task-specific context rather than receiving general tenant access.

SECURITY IN PRACTICE

Understandable protections without exposing internal architecture.

We publish what a prospect needs to evaluate LucenOne without turning this page into an exploitable architecture diagram.

Untrusted sources by default

Incoming sources are treated as untrusted. File types, active content, executables, abnormal archives and malicious signals are part of ingestion controls.

Isolated access

Permissions apply at organization, entity and case level. The interface is not the security boundary.

Server-side keys and secrets

Technical keys and processing secrets are not exposed to the browser.

Limited AI context

An AI capability receives only information authorized and necessary for the requested task.

Useful traceability

Important operations, corrections and validations are designed to stay auditable without overwhelming the case with technical logs.

Human decision maker

AI results can be reviewed, corrected, completed or rejected by authorized users.

NO TRAINING: WHAT THAT MEANS

Processing context is not learning from your cases.

An AI capability may need some authorized case content to perform a task. That content does not thereby become shared knowledge or a training corpus.

1

Authorized context

Only information useful and accessible for the task is selected.

2

Requested processing

The context is used to produce the expected analysis for this case.

3

No client-data training

Content is not reused to train models or shared between customers.

FREQUENT QUESTIONS

Answers security, legal and compliance teams should get immediately.

Is my data used to train AI?

No. Client case content is not used to train the models used by LucenOne. An AI capability may process context required for an authorized task without authorizing training or reuse for other customers.

Can information from one case appear in another?

No. One case is not used to answer inside another. Authorized aggregate analyses remain separate and do not make one case’s source content visible inside another.

Where is business data hosted?

LucenOne’s production business-data foundation is hosted in the European Union.

Is LucenOne GDPR compliant?

LucenOne is designed to support GDPR-compliant processing. Complete compliance also depends on the controller’s purpose, legal basis, notices, retention, permissions and procedures.

How does LucenOne approach the EU AI Act?

LucenOne is designed and governed around applicable EU AI Act requirements. Exact qualification depends on the use case and each actor’s regulatory role.

Can an attachment instruct the AI?

Imported content is treated as untrusted data to analyze, never as system instructions. Prompt-injection signals are among the risks considered in the processing chain.

Can AI decide instead of the investigator?

No. LucenOne can connect, flag, propose or explain. Final validation and decision remain human.

TRUST PACKAGE

The core guarantees are here. Specific evidence comes next.

For a security questionnaire, DPA, retention requirement, subprocessor review or specific AI-governance need, LucenOne can provide the evidence appropriate to the evaluation context. A meeting is not required to understand the essential principles.