Skip to content

Security & Trust Center

Controllable AI workflows. Binding privacy guarantees.

Lurus Code is GDPR-compliant on every offered model route. Source code and request context are processed with Zero Data Retention and are not used for training by Lurus or connected model providers.

Binding guarantees

What happens to your code – and what does not

The following statements apply across the product and are rendered from our central trust register.

Source code storage

Lurus Code processes source code and request context with Zero Data Retention.

Context required for a request is transmitted solely for processing and is not retained after processing is complete.

Privacy policy and DPA → Lurus Privacy Reviewed: 2026-07-26

Model training

Customer data and source code are not used to train AI models.

The no-training guarantee applies to Lurus and every model provider connected through Lurus Code.

Model and provider overview → Lurus AI Platform Reviewed: 2026-07-26

Retention and region

Zero Data Retention applies by default to every model and provider route.

Model, provider, and processing region are disclosed transparently for each route without limiting the Zero Data Retention guarantee.

Model and provider overview → Lurus Security & Compliance Reviewed: 2026-07-26

Model and data routes

Transparent region. Identical guarantees.

You can see which provider and processing region a model route uses. The region does not change the binding privacy guarantees.

EU route

Models hosted in Europe

For teams that prefer processing through model and provider routes hosted in Europe.

  • GDPR-compliant
  • Zero Data Retention
  • No training on customer data

US/global route

US-hosted and global models

Selected high-performance models are processed in the US. Provider and region are disclosed transparently before selection.

  • GDPR-compliant
  • Zero Data Retention
  • No training on customer data

Current model and provider overview →

Infrastructure

Assessed hosting infrastructure

Hosting infrastructure: ISO/IEC 27001 certified and C5 attested.

The hosting infrastructure supports secure platform operations and is operated under the stated information-security standards.

Owner: Lurus Security & Compliance Reviewed: 2026-07-26

Technical safeguards

Lurus Code minimizes transmitted context and protects processing at the relevant system boundaries.

01

Protected transport

Requests and required repository context are transmitted securely to the selected model route.

02

Data minimization

Only context required for the specific request and selected tools is transmitted.

03

No permanent code storage

Source code and request context are not retained for later model use after processing is complete.

Agent controls and permissions

Sandbox boundaries, interaction modes, and project rules constrain what the agent may read, change, or execute.

Sandbox and sensitive paths

Workspace boundaries, blocked system paths, and sensitive-file detection protect areas outside the approved context.

Plan as a read-only mode

In plan mode, the agent analyzes and plans without changing files. Additional permission modes govern approval for specific actions.

Persistent decisions

Deliberate “always allow” decisions can be stored per project and reviewed later.

Allow/deny rules

Rules in .lurus/settings.json define which tools, paths, or commands are automatically allowed or denied.

Permission system in detail →

Frequently asked questions

Start securely and stay in control

Try Lurus Code free for one week or explore the concrete engineering workflow in the demo.