Source code storage
Lurus Code processes source code and request context with Zero Data Retention.
Context required for a request is transmitted solely for processing and is not retained after processing is complete.
Your code is never stored. GDPR-compliant processing with immediate data deletion.
View our security standardsSecurity & Trust Center
Lurus Code is GDPR-compliant on every offered model route. Source code and request context are processed with Zero Data Retention and are not used for training by Lurus or connected model providers.
Binding guarantees
The following statements apply across the product and are rendered from our central trust register.
Source code storage
Context required for a request is transmitted solely for processing and is not retained after processing is complete.
Model training
The no-training guarantee applies to Lurus and every model provider connected through Lurus Code.
Retention and region
Model, provider, and processing region are disclosed transparently for each route without limiting the Zero Data Retention guarantee.
Model and data routes
You can see which provider and processing region a model route uses. The region does not change the binding privacy guarantees.
EU route
For teams that prefer processing through model and provider routes hosted in Europe.
US/global route
Selected high-performance models are processed in the US. Provider and region are disclosed transparently before selection.
Infrastructure
Hosting infrastructure: ISO/IEC 27001 certified and C5 attested.
The hosting infrastructure supports secure platform operations and is operated under the stated information-security standards.
Lurus Code minimizes transmitted context and protects processing at the relevant system boundaries.
01
Requests and required repository context are transmitted securely to the selected model route.
02
Only context required for the specific request and selected tools is transmitted.
03
Source code and request context are not retained for later model use after processing is complete.
Sandbox boundaries, interaction modes, and project rules constrain what the agent may read, change, or execute.
Workspace boundaries, blocked system paths, and sensitive-file detection protect areas outside the approved context.
In plan mode, the agent analyzes and plans without changing files. Additional permission modes govern approval for specific actions.
Deliberate “always allow” decisions can be stored per project and reviewed later.
Rules in .lurus/settings.json define which tools, paths, or commands are automatically allowed or denied.
Binding details about processing, contracts, model routes, and agent controls.
Yes. GDPR compliance applies to every offered model route. Provider and processing region are disclosed transparently, whether a route is hosted in Europe or the US.
Yes. Zero Data Retention is a binding requirement for every offered model and provider route, including routes hosted in the US.
No. Customer data, prompts, and source code are not used to train AI models by Lurus or connected model providers.
The processing region depends on the selected model route. Lurus Code offers routes hosted in Europe and the US or globally, and discloses provider and region in the model overview.
The hosting infrastructure is ISO/IEC 27001 certified and C5 attested.
Sandbox boundaries, read-only plan mode, configurable permission modes, persistent decisions, and allow/deny rules govern which actions the agent may execute.
Try Lurus Code free for one week or explore the concrete engineering workflow in the demo.