Trust Center
This page states where Luscent runs, what it holds, who can reach it, and what is not yet true. Luscent is a seed-stage company and does not hold a security certification. Everything below is written so that a reviewer can check it rather than take it on trust.
- Client data residency
- European Union only
- Primary region
- Scaleway PAR-2, Paris, France
- Disaster recovery region
- Scaleway WAW-2, Warsaw, Poland
- AI inference
- Open-weight models, Scaleway EU platform
- Non-EU model APIs in the client-data path
- None
- Sub-processors with access to client data
- One
- Encryption at rest
- AES-256
- Encryption in transit
- TLS 1.3 public, WireGuard internal
- Client notification after a confirmed breach
- Within 24 hours
- ISO/IEC 27001
- Controls aligned, certification not held
All client data stays in the European Union
Luscent stores and processes all client data in the European Union. The primary region is Scaleway PAR-2 in Paris, France. The disaster recovery region is Scaleway WAW-2 in Warsaw, Poland. Luscent's own code, identity and internal communications run inside the Microsoft EU Data Boundary and hold no client data.
One Luscent sub-processor is not established in the European Union. Tailscale is a United States company and provides the encrypted mesh network between Luscent's own instances. Tailscale receives connection metadata. It does not receive client data, because traffic runs peer to peer over WireGuard directly between Luscent machines rather than through Tailscale servers. Luscent states this here rather than leaving it to be discovered in a questionnaire.
Data classification
Luscent classifies data in four levels and maps each level to a zone. Client data is class C4 and is held only in Scaleway PAR-2 and its Warsaw replica.
| Class | Contents | Zone | Protection |
|---|---|---|---|
| C1 Public | Marketing site, open-source contributions | Microsoft EU | TLS in transit |
| C2 Internal | Internal documentation, architecture decisions | Microsoft EU | TLS, encrypted at rest |
| C3 Confidential | Business communications, contracts, investor material | Microsoft EU | TLS, encrypted at rest, information protection labels |
| C4 Restricted | Client relationship data, communication metadata, Signal outputs, financial summaries | Scaleway PAR-2 | TLS 1.3, AES-256 at rest, WireGuard tunnel |
Encrypted on every hop
Client data reaches Luscent over TLS 1.3 and moves between Luscent services over WireGuard inside a private mesh with no public endpoints. It is written to a managed PostgreSQL database and to object storage encrypted with AES-256 at rest, and replicated encrypted to Warsaw. Backups are encrypted to the same standard as their source.
| Scope | Standard | Implementation |
|---|---|---|
| In transit, public | TLS 1.3 | Managed certificates with automatic renewal, HSTS enforced |
| In transit, internal | WireGuard | ChaCha20-Poly1305 across the Tailscale mesh |
| At rest, database | AES-256 | Scaleway managed encryption, keys held in Scaleway KMS |
| At rest, object storage | AES-256 | Server-side encryption, private bucket policy, versioning enabled |
| Backups | AES-256 | Encrypted to the same standard as the source |
Encryption keys for data at rest are held in Scaleway's key management service. Customer-managed keys are not available today and are on the roadmap after the Series A.
Where the record itself lives
A firm that already runs a CRM keeps it, and Luscent reads from it. A firm without one can use the Luscent CRM, which Luscent builds in-house. It is deliberately lightweight, it runs inside the same Paris deployment behind the same private network and API boundary as the rest of the platform, and it is not a third-party product. Choosing it adds no sub-processor to the list in section 05.
Inference runs in Paris, on open-weight models
Luscent runs open-weight language models on Scaleway's EU inference platform in Paris. No OpenAI, Anthropic, Google or other non-EU model API sits in the path of client data. Inference happens on the same European infrastructure that holds the data, which is why Luscent can describe residency as a property of the whole system rather than of storage alone.
Training
Luscent does not use client data to train or fine-tune models. Luscent consumes models as served infrastructure and does not contribute client data to model training, either its own or a third party's.
Human review
Luscent staff do not read client data as a matter of course. Access to production data is limited to investigating a fault or responding to a client request, is performed by named individuals under the access controls described in section 07, and is logged.
Deterministic where it matters
Luscent's compliance checks run on a deterministic rules engine, not on a language model. A rule produces the same result on the same input every time, which is the property an auditor needs and the property a probabilistic model does not have. Language models are used to read and summarise communications; they do not decide whether an obligation is met.
EU AI Act
Luscent is a provider of an AI system under Regulation (EU) 2024/1689. The Article 50 transparency obligations applied on 2 August 2026. The high-risk regime was rescheduled by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Luscent's documented Article 50 position is available to clients and prospects on request. Luscent does not describe itself as compliant with an obligation before that is true.
Three sub-processors. One touches client data.
Luscent publishes its complete sub-processor list here and updates it when it changes. Jurisdiction is the second column because it is the second question.
| Sub-processor | Jurisdiction | Purpose | Data | Agreement |
|---|---|---|---|---|
| Scaleway (Iliad Group) | France (PAR-2), Poland (WAW-2) | Compute, managed database, object storage, GPU inference | C4. Client relationship data and Signal outputs | Article 28 terms in Scaleway's data processing agreement |
| Microsoft | Microsoft EU Data Boundary | Identity (Entra ID), source control (Azure DevOps), internal communications (Microsoft 365) | C1 to C3. Code, internal documents, business communications. No client data. | Microsoft Products and Services Data Protection Addendum |
| Tailscale | United States | Encrypted mesh network between Luscent services | Network metadata only. Traffic is peer-to-peer over WireGuard and does not transit Tailscale servers. | Tailscale data processing agreement |
Where Luscent's people are
Luscent's leadership is in Luxembourg and Germany. Luscent's engineering team is engaged through an employer of record in Brazil. Luscent states this plainly because a reviewer will establish it in ten minutes and should not have to.
What bounds that access is written down and testable. Engineering access to production runs through Microsoft Entra ID with multi-factor authentication enforced, and through tag-based access control on the Tailscale mesh. No engineer holds direct access to the production database. Production changes reach production only through the deployment pipeline. Development and staging environments contain no client data. Access is revoked from a single checklist on departure.
Personal data of Luscent staff is processed by the employer of record. Client data is not.
Luscent does not hold a security certification
Luscent has mapped its controls to ISO/IEC 27001:2022 and that work is continuous. Luscent does not hold the certificate and does not describe itself as certified. Certification requires an accredited external audit, which is planned after the Series A. A SOC 2 Type I report is planned for 2027 and a Type II report for 2028.
| Standard | Status | Target |
|---|---|---|
| ISO/IEC 27001 | Controls aligned, certification not held | Certification planned post-Series A, 2027 |
| SOC 2 Type I | Not held | Planned 2027 |
| SOC 2 Type II | Not held | Planned 2028 |
Regulation that applies to Luscent as a company
These are obligations on Luscent as your supplier. DORA appears in this table and in no other, because DORA describes how Luscent operates as an ICT third-party service provider. It is not a feature of the Luscent product and Luscent does not present it as one.
| Regulation | Instrument | Status | What it means here |
|---|---|---|---|
| GDPR | Regulation (EU) 2016/679 | Applies | Luscent is a processor of client data and a controller of its own business data. |
| DORA | Regulation (EU) 2022/2554 | Applies as ICT third-party provider | Luscent supports its clients' Article 28 register and due-diligence obligations. Evidence available on request. |
| EU AI Act | Regulation (EU) 2024/1689 | Applies as provider | Article 50 transparency obligations applied on 2 August 2026. Luscent's Article 50 position is documented and available on request. |
| NIS2 | Directive (EU) 2022/2555 | Monitored | Applicability follows client sector and Luxembourg transposition. |
Regulation the product helps you evidence
These are obligations on you. Luscent produces the record that evidences them. The distinction between this table and the one above is deliberate: a supplier that blurs the two is describing its own compliance as though it were yours.
| Regulation | What Luscent produces |
|---|---|
| MiFID II | Suitability evidence and audit trail |
| GDPR | Lawful basis records, retention, subject-request support |
| FinSA and FinIA | Swiss suitability and documentation |
| CVM and ANBIMA | Resolutions 30, 178, 35, 19 and 50 |
| LGPD | Brazilian data-protection acknowledgment |
What is in place, and what is not
Luscent is a seed-stage company. Its technical controls are ahead of its organisational ones, which is the normal shape at this size and is stated here rather than smoothed over. A control that is partial is labelled partial.
Identity and access
| Control | Status | Implementation |
|---|---|---|
| Multi-factor authentication | In place | Enforced for every Luscent staff account through Microsoft Entra ID. |
| Least privilege | In place | Administrative infrastructure access is held by two people. Engineers cannot reach the production database directly. |
| Network access control | In place | Tag-based access lists across the Tailscale mesh. Internal services have no public endpoint. |
| Offboarding | In place | Identity deactivation, mesh removal and repository revocation run from a single checklist on departure. |
| Periodic access review | Planned | Quarterly recertification of privileged access. |
Engineering and change
| Control | Status | Implementation |
|---|---|---|
| Peer review | In place | Branch protection on the main branch. No change reaches production without a reviewed pull request. |
| Deployment path | In place | Production changes ship only through the pipeline. Manual deployment is not available. |
| Environment separation | In place | Development, staging and production are separate instances on separate network tags. Development and staging hold no client data. |
| Infrastructure as code | In place | Infrastructure is declared in version control and applied from the pipeline. |
| Dependency auditing | Partial | Dependency advisories are checked in continuous integration. A dedicated scanning platform is planned. |
| Secure coding standard | Partial | Static analysis and type-level enforcement are in place. A written standard and formal threat modelling are planned. |
Monitoring and operations
| Control | Status | Implementation |
|---|---|---|
| Application and infrastructure monitoring | In place | Metrics and logs with alerting on critical errors and resource thresholds. |
| Network access logging | In place | Every mesh connection event is recorded. |
| Time synchronisation | In place | All instances synchronised, all log timestamps in UTC. |
| Central security event platform | Planned | Log aggregation into a single security monitoring platform is planned. Daily review and critical-error alerting are the current controls. |
Policy and organisation
| Control | Status | Implementation |
|---|---|---|
| Information security policy | Partial | Drafted. Formal approval is scheduled for the first board meeting after the RCS filing. |
| Named security roles | In place | A security lead, an infrastructure owner, an application security owner and an executive accountable for every external security claim. |
| Segregation of duties | In place | Two-person integrity for production change. |
| Confidentiality undertakings | In place | Signed by every member of staff and every contractor. |
| Security awareness training | Partial | Security onboarding is in place. Recurring formal training is planned. |
| Device management | Partial | Full-disk encryption is enforced. Centrally managed devices are planned. |
Luscent is your processor, not your controller
For client data, you are the controller and Luscent is the processor under Article 28 of Regulation (EU) 2016/679. Luscent processes client data only on your documented instructions. For Luscent's own business data, such as the details of the people it contracts with, Luscent is the controller.
Luscent signs a data processing agreement with every client. The template is available before any commercial commitment, so that your legal review can start at the same time as your technical one rather than after it. Write to legal@luscent.io for the template.
Data subject requests
Where a data subject exercises a right against you as controller and the data sits in Luscent, Luscent assists with access, rectification, erasure and portability within the timeframes set by the data processing agreement. Requests go to privacy@luscent.io.
Brazil
Luscent acknowledges the Lei Geral de Protecao de Dados for Brazilian client data and maintains the corresponding records. Brazilian engineering personnel access is described in section 05.
Retention
Client data is retained for the term of the agreement and deleted or returned on termination as set out in the data processing agreement. Operational retention periods are below.
| Record | Retention |
|---|---|
| Database backups and point-in-time recovery | 30 days |
| Application and infrastructure logs | 30 days |
| Network access logs | 90 days |
| Identity and sign-in audit logs | 30 days |
Recovery objectives
Luscent runs a high-availability managed database in Paris with automatic failover, and an encrypted replica in Warsaw for regional failure. Backups run automatically with 30 days of point-in-time recovery. The figures below are design objectives for the architecture as deployed.
| Scenario | Recovery point objective | Recovery time objective |
|---|---|---|
| Single instance failure | No data loss | Under 5 minutes |
| Database failure | Under 1 minute | Under 15 minutes |
| Loss of the Paris region | Under 1 hour | Under 4 hours |
| Data corruption | Under 24 hours | Under 2 hours |
| Complete infrastructure loss | Under 24 hours | Under 8 hours |
Clients hear within 24 hours
Luscent commits to notifying affected clients within 24 hours of confirming a security incident that affects their data. Article 33 of the GDPR allows 72 hours for notification to a supervisory authority. Luscent sets its own commitment 48 hours inside that ceiling, because a client who learns late cannot act at all.
| Phase | Commitment | Detail |
|---|---|---|
| Detection | Continuous | Automated monitoring and alerting |
| Classification | Within 1 hour | Severity assigned, P1 to P4 |
| Containment | Within 2 hours for P1 | Within 8 hours for P2 |
| Client notification | Within 24 hours | More restrictive than the 72 hours allowed by GDPR Article 33 |
| Root cause analysis | Within 5 business days | Technical review |
| Post-incident report | Within 10 business days | Written and shared |
Reporting a vulnerability
Security researchers should write to security@luscent.io. Luscent asks for a reasonable period to remediate before public disclosure, and does not pursue legal action against good-faith research conducted on those terms.
Available now
Luscent does not gate the two documents a reviewer needs first. The sub-processor list is on this page and the data processing agreement is available before any commercial commitment. The rest arrive by return of email rather than through a portal, because at Luscent's size a portal would be theatre.
| Document | Access | Notes |
|---|---|---|
| Data processing agreement | On request | Article 28 template, available before commercial commitment |
| Sub-processor list | Public | Published on this page and updated when it changes |
| Architecture and data-residency overview | On request | Two-zone architecture with regions and data classes |
| DORA Article 28 information pack | On request | For a client's register of information and due diligence file |
| EU AI Act Article 50 position | On request | Documented provider assessment |
| Security questionnaire response | On request | Completed against the reviewer's own format |
The questions a review actually asks
Grouped in the order a review runs. Every answer is written to stand on its own, so it can be pasted straight into a questionnaire, and every question has its own link, so an answer can be sent on without sending the whole page.
What Luscent holds
Where does Luscent store client data?#
Luscent stores and processes all client data in the European Union. The primary region is Scaleway PAR-2 in Paris, France, and the disaster recovery region is Scaleway WAW-2 in Warsaw, Poland. No client data is stored or processed outside the European Union.
Does client data ever leave the European Union?#
No. Luscent stores client data, processes it and runs model inference on it entirely within the European Union, and no non-EU model API sits in the path of client data. One Luscent sub-processor is established outside the European Union: Tailscale, a United States company, provides the encrypted network between Luscent's own machines and receives connection metadata only, because that traffic runs peer to peer rather than through Tailscale servers.
What client data does Luscent hold?#
Luscent holds client relationship records, communication metadata, the Signals and Health Scores the platform derives from them, and financial summaries such as assets under management. Luscent classifies all of this as C4, its most restricted class, which is held only in Scaleway PAR-2 in Paris and its encrypted replica in Warsaw.
The Luscent CRM and integrations
What is the Luscent CRM, and is it a third-party product?#
The Luscent CRM is built in-house by Luscent. It is not a third-party product, and Luscent does not bundle or resell another vendor's CRM. It is deliberately lightweight: it holds client records, activity history and relationship data for firms that do not already run a CRM. It runs on the same Scaleway infrastructure in Paris as the rest of the platform, behind the same private network and the same API boundary, and it introduces no additional sub-processor.
Does Luscent require a firm to replace its existing CRM?#
No. Luscent is an intelligence layer over the systems a firm already runs. A firm with an existing CRM such as Salesforce keeps it, and Luscent integrates with it. A firm without one can use the Luscent CRM, which is included. The system of record stays wherever the firm wants it.
Which systems does Luscent connect to?#
Luscent integrates with Microsoft 365 and with Salesforce, and includes its own in-house CRM for firms that do not run one. Each connection is authorised by the firm through the provider's own consent flow and is scoped to what the firm chooses to share.
AI
Which AI models does Luscent use, and where do they run?#
Luscent runs open-weight language models on Scaleway's EU inference platform in Paris. No OpenAI, Anthropic, Google or other non-EU model API sits in the path of client data. Model inference happens on the same European infrastructure that holds the data.
Does Luscent train models on client data?#
No. Luscent does not use client data to train or fine-tune models. Luscent runs open-weight models as served infrastructure and does not contribute client data to model training, either its own or a third party's.
Does a language model decide whether a firm is compliant?#
No. Luscent's compliance checks run on a deterministic rules engine, not on a language model. A rule produces the same result on the same input every time, which is the property an auditor needs and the property a probabilistic model does not have. Language models are used to read and summarise communications; they do not decide whether an obligation is met.
How is Luscent classified under the EU AI Act?#
Luscent is a provider of an AI system under Regulation (EU) 2024/1689. The Article 50 transparency obligations applied on 2 August 2026. The high-risk regime was rescheduled by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Luscent's documented Article 50 position is available to clients and prospects on request.
Who can reach it
Who at Luscent can access client data?#
Access to production systems is limited to named individuals under enforced multi-factor authentication and tag-based network access control. Administrative infrastructure access is held by two people. No engineer holds direct access to the production database. Luscent staff do not read client data as a matter of course: access happens to investigate a fault or to answer a client request, and it is logged.
Where are Luscent's engineers located?#
Luscent's leadership is in Luxembourg and Germany. Luscent's engineering team is engaged through an employer of record in Brazil. Engineering access to production is governed by enforced multi-factor authentication, tag-based network access control and a pipeline-only deployment path, and no engineer holds direct production database access. Development and staging environments contain no client data.
Does Luscent support single sign-on?#
Yes. Luscent authenticates users through Microsoft Entra ID single sign-on, and session policy is configurable per client firm.
Which sub-processors have access to client data?#
One. Scaleway processes client data as Luscent's infrastructure provider in France and Poland. Microsoft holds Luscent's own code, documents and internal communications and does not receive client data. Tailscale carries network metadata only, because traffic between Luscent services is peer to peer and does not transit Tailscale servers.
Does Luscent use any United States sub-processor?#
Yes, one. Tailscale is a United States company and provides Luscent's encrypted internal network. Tailscale receives connection metadata only. Client data does not reach Tailscale servers, because traffic runs peer to peer over WireGuard directly between Luscent's own instances.
Certifications and regulation
Is Luscent ISO 27001 certified?#
No. Luscent has mapped its controls to ISO/IEC 27001:2022 but does not hold the certification. Formal certification is planned after the Series A, targeted for 2027. Luscent will not describe itself as certified before an accredited auditor has issued the certificate.
Is Luscent SOC 2 compliant?#
No. Luscent does not hold a SOC 2 report. A SOC 2 Type I report is planned for 2027 and a Type II report for 2028.
Does Luscent hold a DORA registration?#
DORA does not create a registration for ICT providers of Luscent's size. Luscent operates as an ICT third-party service provider to financial entities and supports its clients' obligations under Article 28 of Regulation (EU) 2022/2554, including the information required for their register of information. DORA is a statement about how Luscent operates, not a feature of the Luscent product.
Is Luscent a controller or a processor of client data?#
For client data, the client firm is the controller and Luscent is the processor under Article 28 of Regulation (EU) 2016/679. Luscent processes client data only on the firm's documented instructions. For Luscent's own business data, such as the details of the people it contracts with, Luscent is the controller.
Contracts, exit and incidents
Can Luscent sign a data processing agreement?#
Yes. Luscent signs a data processing agreement under Article 28 of the GDPR with every client. The template is available on request before any commercial commitment.
What happens to client data when an agreement ends?#
Client data is retained for the term of the agreement and is deleted or returned on termination, as set out in the data processing agreement. Backups age out of the 30-day point-in-time recovery window that applies to the production database.
How quickly does Luscent notify clients of a security incident?#
Within 24 hours of confirming a security incident affecting client data. This is more restrictive than the 72 hours that Article 33 of the GDPR allows for notification to a supervisory authority.
What is Luscent's legal entity?#
Luscent S.A., a société anonyme in formation in Luxembourg, with its registered office at House of Startups, 9 Rue du Laboratoire, L-1911 Luxembourg. The company is in formation and its registration number will be published here once the filing with the Registre de Commerce et des Sociétés is complete.
Who does a security researcher contact?#
security@luscent.io. Luscent asks researchers to allow a reasonable period for remediation before public disclosure and does not pursue legal action against good-faith research conducted under those terms.
- Security and vulnerability reports
- security@luscent.io
- Privacy and data subject requests
- privacy@luscent.io
- Contracts and data processing agreements
- legal@luscent.io
- Legal entity
- Luscent S.A. (in formation)
- Registered office
- House of Startups, 9 Rue du Laboratoire, L-1911 Luxembourg
Luscent S.A. is in formation. Its registration number will be published on this page once the filing with the Registre de Commerce et des Sociétés is complete. This page was last reviewed on and is updated when the underlying architecture, sub-processor list or certification status changes.