LightOn icon

LightOn

Sovereign enterprise GenAI platform deployed on-prem, air-gapped, or EU cloud

by LightOnFRFrance🌐EU infrastructure; on-premise, VPC, or air-gapped within customer perimeter
TrustKit Score88%Excellent

About LightOn

LightOn is a French generative AI company founded in 2016 in Paris and headquartered there. In November 2024 it became the first pure-play generative AI company to list on Euronext Growth Paris (ticker ALTAI), positioning itself as a flagship of Europe's sovereign AI movement. Its core product, Paradigm, is a turnkey enterprise GenAI platform providing retrieval-augmented generation (RAG), intelligent agents, document analysis, and custom assistants over an organisation's own data. Paradigm's defining feature is its deployment model: rather than sending data to an external API, LightOn brings the AI to the customer's data. The platform can be installed on-premise, inside a customer VPC, or in fully air-gapped environments, keeping all data within the client's own security perimeter. This makes it suitable for highly sensitive public-sector and regulated enterprise workloads — customers include the Île-de-France region, Safran, Groupama, CNES (French space agency), and the Direction Générale des Finances Publiques. LightOn has trained more than a dozen large language models since 2020 and publishes notable open-source models and libraries (including ModernBERT, BioClinical ModernBERT, and PyLate). Paradigm is model-agnostic and can run open-weight models within the customer's perimeter, so no customer data is used to train shared models. The company holds SOC 2 Type 1 certification and states full GDPR and EU AI Act compliance. Because it is an EU-incorporated, Euronext-listed French company with no US parent, and because its architecture defaults to in-perimeter deployment, LightOn scores very strongly on data sovereignty. The main caveats for the most demanding French public-sector buyers are that its published certification is SOC 2 Type 1 (not Type II) and that ANSSI SecNumCloud qualification appears to be a positioning goal rather than a confirmed, published qualification at the time of writing.

TrustKit Score Breakdown

?88% Excellent
Data Residency
Where is your data stored and processed?
Deploys on-premise, in customer VPC, or air-gapped on EU infrastructure, so data never leaves the customer's own security perimeter. Strongest possible residency posture.
5/5
Legal Jurisdiction
Which laws govern the company and your data?
French SA incorporated in France, listed on Euronext Growth Paris, with no US parent. Fully under EU/French jurisdiction.
5/5
Data Retention & Training
Is your data used for model training?
In-perimeter deployment means no customer data is sent out or used to train shared models, and retention is governed by the customer's own infrastructure. Scored 4 rather than 5 as public DPA/retention-control documentation is limited.
4/5
Certifications
ISO 27001, SOC 2, Cyber Essentials, etc.
Holds SOC 2 Type 1. ISO 27001 and SOC 2 Type II are not confirmed in published sources, and ANSSI SecNumCloud appears to be a positioning goal rather than a confirmed qualification.
3/5
Regulatory Fit
Suitability for regulated industries and professional services
Purpose-built for regulated and sovereign EU buyers, with public-sector and defense/aerospace references (CNES, Safran, French tax authority) and GDPR/AI Act alignment.
5/5

Pricing

Custom
EnterpriseContact Sales
Full pricing details →

Quick Facts

Starting PriceCustom enterprise pricingData HostingEU infrastructure; on-premise, VPC, or air-gapped within customer perimeterTrains on Your DataNo training on customer data; in-perimeter deployment keeps data isolatedFounded2016Employees11-50

Frequently Asked Questions

Is LightOn GDPR compliant?

LightOn has a TrustKit compliance score of 88% (Excellent). Data Residency: Deploys on-premise, in customer VPC, or air-gapped on EU infrastructure, so data never leaves the customer's own security perimeter. Strongest possible residency posture.. Legal Jurisdiction: French SA incorporated in France, listed on Euronext Growth Paris, with no US parent. Fully under EU/French jurisdiction..

Where does LightOn store data?

LightOn hosts data in: EU infrastructure; on-premise, VPC, or air-gapped within customer perimeter. Deploys on-premise, in customer VPC, or air-gapped on EU infrastructure, so data never leaves the customer's own security perimeter. Strongest possible residency posture.

Does LightOn train on user data?

LightOn: No training on customer data; in-perimeter deployment keeps data isolated. In-perimeter deployment means no customer data is sent out or used to train shared models, and retention is governed by the customer's own infrastructure. Scored 4 rather than 5 as public DPA/retention-control documentation is limited.

What certifications does LightOn hold?

LightOn holds: SOC 2 Type 1. Holds SOC 2 Type 1. ISO 27001 and SOC 2 Type II are not confirmed in published sources, and ANSSI SecNumCloud appears to be a positioning goal rather than a confirmed qualification.

Compare LightOn With

Similar Tools

Related Articles