Trust CenterLast reviewed

Trust Center

This page states where Luscent runs, what it holds, who can reach it, and what is not yet true. Luscent is a seed-stage company and does not hold a security certification. Everything below is written so that a reviewer can check it rather than take it on trust.

[01] At a glanceThe ten facts most reviewers open this page for
Client data residency
European Union only
Primary region
Scaleway PAR-2, Paris, France
Disaster recovery region
Scaleway WAW-2, Warsaw, Poland
AI inference
Open-weight models, Scaleway EU platform
Non-EU model APIs in the client-data path
None
Sub-processors with access to client data
One
Encryption at rest
AES-256
Encryption in transit
TLS 1.3 public, WireGuard internal
Client notification after a confirmed breach
Within 24 hours
ISO/IEC 27001
Controls aligned, certification not held
[02] Where your data livesFig. 1

All client data stays in the European Union

Luscent stores and processes all client data in the European Union. The primary region is Scaleway PAR-2 in Paris, France. The disaster recovery region is Scaleway WAW-2 in Warsaw, Poland. Luscent's own code, identity and internal communications run inside the Microsoft EU Data Boundary and hold no client data.

One Luscent sub-processor is not established in the European Union. Tailscale is a United States company and provides the encrypted mesh network between Luscent's own instances. Tailscale receives connection metadata. It does not receive client data, because traffic runs peer to peer over WireGuard directly between Luscent machines rather than through Tailscale servers. Luscent states this here rather than leaving it to be discovered in a questionnaire.

Fig. 1Luscent | Trust CenterAll Luscent client data is held inside the European Union across three zones: Microsoft EU Data Boundary for identity, code and internal communications; Scaleway PAR-2 in Paris for the application, database, storage and AI inference; and Scaleway WAW-2 in Warsaw for encrypted disaster recovery. Tailscale, a United States company, sits outside the boundary and receives network metadata only.EUROPEAN UNIONZone 1 · Microsoft EU Data BoundaryIdentity, source control, internal communicationsData classes C1 to C3. No client data.Zone 2 · Scaleway PAR-2, ParisApplication, managed database, object storage, GPU inferenceData class C4. All client data.Zone 3 · Scaleway WAW-2, WarsawEncrypted replica for disaster recoveryData class C4. Encrypted replication.metadataTailscaleUnited StatesNetwork metadata only
Luscent runs in three EU zones. The one sub-processor outside the European Union is drawn outside the boundary, in dashes, carrying network metadata only.

Data classification

Luscent classifies data in four levels and maps each level to a zone. Client data is class C4 and is held only in Scaleway PAR-2 and its Warsaw replica.

ClassContentsZoneProtection
C1 PublicMarketing site, open-source contributionsMicrosoft EUTLS in transit
C2 InternalInternal documentation, architecture decisionsMicrosoft EUTLS, encrypted at rest
C3 ConfidentialBusiness communications, contracts, investor materialMicrosoft EUTLS, encrypted at rest, information protection labels
C4 RestrictedClient relationship data, communication metadata, Signal outputs, financial summariesScaleway PAR-2TLS 1.3, AES-256 at rest, WireGuard tunnel
[03] How data movesFig. 2

Encrypted on every hop

Client data reaches Luscent over TLS 1.3 and moves between Luscent services over WireGuard inside a private mesh with no public endpoints. It is written to a managed PostgreSQL database and to object storage encrypted with AES-256 at rest, and replicated encrypted to Warsaw. Backups are encrypted to the same standard as their source.

Fig. 2Luscent | Trust CenterClient data travels from client systems over TLS 1.3 to Luscent ingest in Paris, then over WireGuard to processing and inference, then to the database and object storage encrypted with AES-256 at rest, and is replicated encrypted to Warsaw for disaster recovery. Every stage after ingest runs on Luscent infrastructure inside the European Union.Client systemsMicrosoft 365SalesforceIngestScaleway PAR-2ParisProcessing andinferenceScaleway PAR-2, ParisDatabase and storageScaleway PAR-2ParisDisaster recoveryScaleway WAW-2WarsawTLS 1.3WireGuardWireGuardReplicationAES-256 at restLUSCENT INFRASTRUCTURE · EUROPEAN UNION
The path a record takes, with the protection applied on each hop. Everything after ingest is Luscent infrastructure inside the European Union.
ScopeStandardImplementation
In transit, publicTLS 1.3Managed certificates with automatic renewal, HSTS enforced
In transit, internalWireGuardChaCha20-Poly1305 across the Tailscale mesh
At rest, databaseAES-256Scaleway managed encryption, keys held in Scaleway KMS
At rest, object storageAES-256Server-side encryption, private bucket policy, versioning enabled
BackupsAES-256Encrypted to the same standard as the source

Encryption keys for data at rest are held in Scaleway's key management service. Customer-managed keys are not available today and are on the roadmap after the Series A.

Where the record itself lives

A firm that already runs a CRM keeps it, and Luscent reads from it. A firm without one can use the Luscent CRM, which Luscent builds in-house. It is deliberately lightweight, it runs inside the same Paris deployment behind the same private network and API boundary as the rest of the platform, and it is not a third-party product. Choosing it adds no sub-processor to the list in section 05.

[04] AI and your dataThe section procurement now opens first

Inference runs in Paris, on open-weight models

Luscent runs open-weight language models on Scaleway's EU inference platform in Paris. No OpenAI, Anthropic, Google or other non-EU model API sits in the path of client data. Inference happens on the same European infrastructure that holds the data, which is why Luscent can describe residency as a property of the whole system rather than of storage alone.

Training

Luscent does not use client data to train or fine-tune models. Luscent consumes models as served infrastructure and does not contribute client data to model training, either its own or a third party's.

Human review

Luscent staff do not read client data as a matter of course. Access to production data is limited to investigating a fault or responding to a client request, is performed by named individuals under the access controls described in section 07, and is logged.

Deterministic where it matters

Luscent's compliance checks run on a deterministic rules engine, not on a language model. A rule produces the same result on the same input every time, which is the property an auditor needs and the property a probabilistic model does not have. Language models are used to read and summarise communications; they do not decide whether an obligation is met.

EU AI Act

Luscent is a provider of an AI system under Regulation (EU) 2024/1689. The Article 50 transparency obligations applied on 2 August 2026. The high-risk regime was rescheduled by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Luscent's documented Article 50 position is available to clients and prospects on request. Luscent does not describe itself as compliant with an obligation before that is true.

[05] Sub-processors and peopleNames, jurisdictions and what each one can reach

Three sub-processors. One touches client data.

Luscent publishes its complete sub-processor list here and updates it when it changes. Jurisdiction is the second column because it is the second question.

Sub-processorJurisdictionPurposeDataAgreement
Scaleway (Iliad Group)France (PAR-2), Poland (WAW-2)Compute, managed database, object storage, GPU inferenceC4. Client relationship data and Signal outputsArticle 28 terms in Scaleway's data processing agreement
MicrosoftMicrosoft EU Data BoundaryIdentity (Entra ID), source control (Azure DevOps), internal communications (Microsoft 365)C1 to C3. Code, internal documents, business communications. No client data.Microsoft Products and Services Data Protection Addendum
TailscaleUnited StatesEncrypted mesh network between Luscent servicesNetwork metadata only. Traffic is peer-to-peer over WireGuard and does not transit Tailscale servers.Tailscale data processing agreement

Where Luscent's people are

Luscent's leadership is in Luxembourg and Germany. Luscent's engineering team is engaged through an employer of record in Brazil. Luscent states this plainly because a reviewer will establish it in ten minutes and should not have to.

What bounds that access is written down and testable. Engineering access to production runs through Microsoft Entra ID with multi-factor authentication enforced, and through tag-based access control on the Tailscale mesh. No engineer holds direct access to the production database. Production changes reach production only through the deployment pipeline. Development and staging environments contain no client data. Access is revoked from a single checklist on departure.

Personal data of Luscent staff is processed by the employer of record. Client data is not.

[06] Certifications and regulationFig. 3

Luscent does not hold a security certification

Luscent has mapped its controls to ISO/IEC 27001:2022 and that work is continuous. Luscent does not hold the certificate and does not describe itself as certified. Certification requires an accredited external audit, which is planned after the Series A. A SOC 2 Type I report is planned for 2027 and a Type II report for 2028.

Fig. 3Luscent | Trust CenterLuscent has aligned its controls to ISO/IEC 27001:2022 and this work is continuous. Luscent does not hold the ISO/IEC 27001 certificate; certification is planned for 2027. A SOC 2 Type I report is planned for 2027 and a SOC 2 Type II report for 2028.2026 H22027 H12027 H22028 H12028 H2ISO/IEC 27001 controls alignedIN PLACEISO/IEC 27001 certificationPLANNEDSOC 2 Type IPLANNEDSOC 2 Type IIPLANNEDtoday
Solid means in place today. Dashed means planned and not held. There is no third style, because there is no third state worth inventing.
StandardStatusTarget
ISO/IEC 27001Controls aligned, certification not heldCertification planned post-Series A, 2027
SOC 2 Type INot heldPlanned 2027
SOC 2 Type IINot heldPlanned 2028

Regulation that applies to Luscent as a company

These are obligations on Luscent as your supplier. DORA appears in this table and in no other, because DORA describes how Luscent operates as an ICT third-party service provider. It is not a feature of the Luscent product and Luscent does not present it as one.

RegulationInstrumentStatusWhat it means here
GDPRRegulation (EU) 2016/679AppliesLuscent is a processor of client data and a controller of its own business data.
DORARegulation (EU) 2022/2554Applies as ICT third-party providerLuscent supports its clients' Article 28 register and due-diligence obligations. Evidence available on request.
EU AI ActRegulation (EU) 2024/1689Applies as providerArticle 50 transparency obligations applied on 2 August 2026. Luscent's Article 50 position is documented and available on request.
NIS2Directive (EU) 2022/2555MonitoredApplicability follows client sector and Luxembourg transposition.

Regulation the product helps you evidence

These are obligations on you. Luscent produces the record that evidences them. The distinction between this table and the one above is deliberate: a supplier that blurs the two is describing its own compliance as though it were yours.

RegulationWhat Luscent produces
MiFID IISuitability evidence and audit trail
GDPRLawful basis records, retention, subject-request support
FinSA and FinIASwiss suitability and documentation
CVM and ANBIMAResolutions 30, 178, 35, 19 and 50
LGPDBrazilian data-protection acknowledgment
[07] Security controlsPartial is written as partial

What is in place, and what is not

Luscent is a seed-stage company. Its technical controls are ahead of its organisational ones, which is the normal shape at this size and is stated here rather than smoothed over. A control that is partial is labelled partial.

Identity and access

ControlStatusImplementation
Multi-factor authenticationIn placeEnforced for every Luscent staff account through Microsoft Entra ID.
Least privilegeIn placeAdministrative infrastructure access is held by two people. Engineers cannot reach the production database directly.
Network access controlIn placeTag-based access lists across the Tailscale mesh. Internal services have no public endpoint.
OffboardingIn placeIdentity deactivation, mesh removal and repository revocation run from a single checklist on departure.
Periodic access reviewPlannedQuarterly recertification of privileged access.

Engineering and change

ControlStatusImplementation
Peer reviewIn placeBranch protection on the main branch. No change reaches production without a reviewed pull request.
Deployment pathIn placeProduction changes ship only through the pipeline. Manual deployment is not available.
Environment separationIn placeDevelopment, staging and production are separate instances on separate network tags. Development and staging hold no client data.
Infrastructure as codeIn placeInfrastructure is declared in version control and applied from the pipeline.
Dependency auditingPartialDependency advisories are checked in continuous integration. A dedicated scanning platform is planned.
Secure coding standardPartialStatic analysis and type-level enforcement are in place. A written standard and formal threat modelling are planned.

Monitoring and operations

ControlStatusImplementation
Application and infrastructure monitoringIn placeMetrics and logs with alerting on critical errors and resource thresholds.
Network access loggingIn placeEvery mesh connection event is recorded.
Time synchronisationIn placeAll instances synchronised, all log timestamps in UTC.
Central security event platformPlannedLog aggregation into a single security monitoring platform is planned. Daily review and critical-error alerting are the current controls.

Policy and organisation

ControlStatusImplementation
Information security policyPartialDrafted. Formal approval is scheduled for the first board meeting after the RCS filing.
Named security rolesIn placeA security lead, an infrastructure owner, an application security owner and an executive accountable for every external security claim.
Segregation of dutiesIn placeTwo-person integrity for production change.
Confidentiality undertakingsIn placeSigned by every member of staff and every contractor.
Security awareness trainingPartialSecurity onboarding is in place. Recurring formal training is planned.
Device managementPartialFull-disk encryption is enforced. Centrally managed devices are planned.
[08] Privacy and your rightsRoles, agreements and requests

Luscent is your processor, not your controller

For client data, you are the controller and Luscent is the processor under Article 28 of Regulation (EU) 2016/679. Luscent processes client data only on your documented instructions. For Luscent's own business data, such as the details of the people it contracts with, Luscent is the controller.

Luscent signs a data processing agreement with every client. The template is available before any commercial commitment, so that your legal review can start at the same time as your technical one rather than after it. Write to legal@luscent.io for the template.

Data subject requests

Where a data subject exercises a right against you as controller and the data sits in Luscent, Luscent assists with access, rectification, erasure and portability within the timeframes set by the data processing agreement. Requests go to privacy@luscent.io.

Brazil

Luscent acknowledges the Lei Geral de Protecao de Dados for Brazilian client data and maintains the corresponding records. Brazilian engineering personnel access is described in section 05.

Retention

Client data is retained for the term of the agreement and deleted or returned on termination as set out in the data processing agreement. Operational retention periods are below.

RecordRetention
Database backups and point-in-time recovery30 days
Application and infrastructure logs30 days
Network access logs90 days
Identity and sign-in audit logs30 days
[09] ResilienceDesign targets, stated as targets

Recovery objectives

Luscent runs a high-availability managed database in Paris with automatic failover, and an encrypted replica in Warsaw for regional failure. Backups run automatically with 30 days of point-in-time recovery. The figures below are design objectives for the architecture as deployed.

ScenarioRecovery point objectiveRecovery time objective
Single instance failureNo data lossUnder 5 minutes
Database failureUnder 1 minuteUnder 15 minutes
Loss of the Paris regionUnder 1 hourUnder 4 hours
Data corruptionUnder 24 hoursUnder 2 hours
Complete infrastructure lossUnder 24 hoursUnder 8 hours
[10] Incident responseFig. 4

Clients hear within 24 hours

Luscent commits to notifying affected clients within 24 hours of confirming a security incident that affects their data. Article 33 of the GDPR allows 72 hours for notification to a supervisory authority. Luscent sets its own commitment 48 hours inside that ceiling, because a client who learns late cannot act at all.

Fig. 4Luscent | Trust CenterLuscent classifies a security incident within one hour of detection, contains a P1 incident within two hours, and notifies affected clients within 24 hours. That is 48 hours inside the 72-hour ceiling set by Article 33 of the GDPR. Root cause analysis follows within five business days and a written report within ten business days.48 hours of margin0Detectioncontinuous monitoring1hClassificationseverity P1 to P42hContainmentP1. P2 within 8h24hClient notifiedLuscent commitment72hGDPR Article 33regulatory ceiling5bdRoot causetechnical review10bdReportwritten and shared
The incident clock. The shaded interval is the margin between Luscent's client-notification commitment and the regulatory ceiling.
PhaseCommitmentDetail
DetectionContinuousAutomated monitoring and alerting
ClassificationWithin 1 hourSeverity assigned, P1 to P4
ContainmentWithin 2 hours for P1Within 8 hours for P2
Client notificationWithin 24 hoursMore restrictive than the 72 hours allowed by GDPR Article 33
Root cause analysisWithin 5 business daysTechnical review
Post-incident reportWithin 10 business daysWritten and shared

Reporting a vulnerability

Security researchers should write to security@luscent.io. Luscent asks for a reasonable period to remediate before public disclosure, and does not pursue legal action against good-faith research conducted on those terms.

[11] DocumentsWhat exists, and how to get it

Available now

Luscent does not gate the two documents a reviewer needs first. The sub-processor list is on this page and the data processing agreement is available before any commercial commitment. The rest arrive by return of email rather than through a portal, because at Luscent's size a portal would be theatre.

DocumentAccessNotes
Data processing agreementOn requestArticle 28 template, available before commercial commitment
Sub-processor listPublicPublished on this page and updated when it changes
Architecture and data-residency overviewOn requestTwo-zone architecture with regions and data classes
DORA Article 28 information packOn requestFor a client's register of information and due diligence file
EU AI Act Article 50 positionOn requestDocumented provider assessment
Security questionnaire responseOn requestCompleted against the reviewer's own format
[12] Questions24 answers, each one linkable

The questions a review actually asks

Grouped in the order a review runs. Every answer is written to stand on its own, so it can be pasted straight into a questionnaire, and every question has its own link, so an answer can be sent on without sending the whole page.

What Luscent holds

Where does Luscent store client data?#

Luscent stores and processes all client data in the European Union. The primary region is Scaleway PAR-2 in Paris, France, and the disaster recovery region is Scaleway WAW-2 in Warsaw, Poland. No client data is stored or processed outside the European Union.

Does client data ever leave the European Union?#

No. Luscent stores client data, processes it and runs model inference on it entirely within the European Union, and no non-EU model API sits in the path of client data. One Luscent sub-processor is established outside the European Union: Tailscale, a United States company, provides the encrypted network between Luscent's own machines and receives connection metadata only, because that traffic runs peer to peer rather than through Tailscale servers.

What client data does Luscent hold?#

Luscent holds client relationship records, communication metadata, the Signals and Health Scores the platform derives from them, and financial summaries such as assets under management. Luscent classifies all of this as C4, its most restricted class, which is held only in Scaleway PAR-2 in Paris and its encrypted replica in Warsaw.

The Luscent CRM and integrations

What is the Luscent CRM, and is it a third-party product?#

The Luscent CRM is built in-house by Luscent. It is not a third-party product, and Luscent does not bundle or resell another vendor's CRM. It is deliberately lightweight: it holds client records, activity history and relationship data for firms that do not already run a CRM. It runs on the same Scaleway infrastructure in Paris as the rest of the platform, behind the same private network and the same API boundary, and it introduces no additional sub-processor.

Does Luscent require a firm to replace its existing CRM?#

No. Luscent is an intelligence layer over the systems a firm already runs. A firm with an existing CRM such as Salesforce keeps it, and Luscent integrates with it. A firm without one can use the Luscent CRM, which is included. The system of record stays wherever the firm wants it.

Which systems does Luscent connect to?#

Luscent integrates with Microsoft 365 and with Salesforce, and includes its own in-house CRM for firms that do not run one. Each connection is authorised by the firm through the provider's own consent flow and is scoped to what the firm chooses to share.

AI

Which AI models does Luscent use, and where do they run?#

Luscent runs open-weight language models on Scaleway's EU inference platform in Paris. No OpenAI, Anthropic, Google or other non-EU model API sits in the path of client data. Model inference happens on the same European infrastructure that holds the data.

Does Luscent train models on client data?#

No. Luscent does not use client data to train or fine-tune models. Luscent runs open-weight models as served infrastructure and does not contribute client data to model training, either its own or a third party's.

Does a language model decide whether a firm is compliant?#

No. Luscent's compliance checks run on a deterministic rules engine, not on a language model. A rule produces the same result on the same input every time, which is the property an auditor needs and the property a probabilistic model does not have. Language models are used to read and summarise communications; they do not decide whether an obligation is met.

How is Luscent classified under the EU AI Act?#

Luscent is a provider of an AI system under Regulation (EU) 2024/1689. The Article 50 transparency obligations applied on 2 August 2026. The high-risk regime was rescheduled by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Luscent's documented Article 50 position is available to clients and prospects on request.

Who can reach it

Who at Luscent can access client data?#

Access to production systems is limited to named individuals under enforced multi-factor authentication and tag-based network access control. Administrative infrastructure access is held by two people. No engineer holds direct access to the production database. Luscent staff do not read client data as a matter of course: access happens to investigate a fault or to answer a client request, and it is logged.

Where are Luscent's engineers located?#

Luscent's leadership is in Luxembourg and Germany. Luscent's engineering team is engaged through an employer of record in Brazil. Engineering access to production is governed by enforced multi-factor authentication, tag-based network access control and a pipeline-only deployment path, and no engineer holds direct production database access. Development and staging environments contain no client data.

Does Luscent support single sign-on?#

Yes. Luscent authenticates users through Microsoft Entra ID single sign-on, and session policy is configurable per client firm.

Which sub-processors have access to client data?#

One. Scaleway processes client data as Luscent's infrastructure provider in France and Poland. Microsoft holds Luscent's own code, documents and internal communications and does not receive client data. Tailscale carries network metadata only, because traffic between Luscent services is peer to peer and does not transit Tailscale servers.

Does Luscent use any United States sub-processor?#

Yes, one. Tailscale is a United States company and provides Luscent's encrypted internal network. Tailscale receives connection metadata only. Client data does not reach Tailscale servers, because traffic runs peer to peer over WireGuard directly between Luscent's own instances.

Certifications and regulation

Is Luscent ISO 27001 certified?#

No. Luscent has mapped its controls to ISO/IEC 27001:2022 but does not hold the certification. Formal certification is planned after the Series A, targeted for 2027. Luscent will not describe itself as certified before an accredited auditor has issued the certificate.

Is Luscent SOC 2 compliant?#

No. Luscent does not hold a SOC 2 report. A SOC 2 Type I report is planned for 2027 and a Type II report for 2028.

Does Luscent hold a DORA registration?#

DORA does not create a registration for ICT providers of Luscent's size. Luscent operates as an ICT third-party service provider to financial entities and supports its clients' obligations under Article 28 of Regulation (EU) 2022/2554, including the information required for their register of information. DORA is a statement about how Luscent operates, not a feature of the Luscent product.

Is Luscent a controller or a processor of client data?#

For client data, the client firm is the controller and Luscent is the processor under Article 28 of Regulation (EU) 2016/679. Luscent processes client data only on the firm's documented instructions. For Luscent's own business data, such as the details of the people it contracts with, Luscent is the controller.

Contracts, exit and incidents

Can Luscent sign a data processing agreement?#

Yes. Luscent signs a data processing agreement under Article 28 of the GDPR with every client. The template is available on request before any commercial commitment.

What happens to client data when an agreement ends?#

Client data is retained for the term of the agreement and is deleted or returned on termination, as set out in the data processing agreement. Backups age out of the 30-day point-in-time recovery window that applies to the production database.

How quickly does Luscent notify clients of a security incident?#

Within 24 hours of confirming a security incident affecting client data. This is more restrictive than the 72 hours that Article 33 of the GDPR allows for notification to a supervisory authority.

What is Luscent's legal entity?#

Luscent S.A., a société anonyme in formation in Luxembourg, with its registered office at House of Startups, 9 Rue du Laboratoire, L-1911 Luxembourg. The company is in formation and its registration number will be published here once the filing with the Registre de Commerce et des Sociétés is complete.

Who does a security researcher contact?#

security@luscent.io. Luscent asks researchers to allow a reasonable period for remediation before public disclosure and does not pursue legal action against good-faith research conducted under those terms.

[13] ContactA person answers each of these
Security and vulnerability reports
security@luscent.io
Privacy and data subject requests
privacy@luscent.io
Contracts and data processing agreements
legal@luscent.io
Legal entity
Luscent S.A. (in formation)
Registered office
House of Startups, 9 Rue du Laboratoire, L-1911 Luxembourg

Luscent S.A. is in formation. Its registration number will be published on this page once the filing with the Registre de Commerce et des Sociétés is complete. This page was last reviewed on and is updated when the underlying architecture, sub-processor list or certification status changes.

The pilotApplications close 30 September 2026

Find out before you move a single client record.

Ninety days, at no cost, with three to five relationship managers, starting on invented clients. Success metrics are agreed in writing before anything is connected, so at the end there is a decision rather than an impression.

90 DAYSCONNECTFIRST SIGNAL ACTED ONREVIEWDAY 0Metrics agreed, in writingWEEK 4The book, rankedWEEK 8A decision on the recordDAY 90Written review90 DAYSNO FEE3 TO 5 SEATSSYNTHETIC FIRSTEU ONLYWRITES BACK NOTHING