LightOn
Sovereign enterprise GenAI platform deployed on-prem, air-gapped, or EU cloud
About LightOn
LightOn is a French generative AI company founded in 2016 in Paris and headquartered there. In November 2024 it became the first pure-play generative AI company to list on Euronext Growth Paris (ticker ALTAI), positioning itself as a flagship of Europe's sovereign AI movement. Its core product, Paradigm, is a turnkey enterprise GenAI platform providing retrieval-augmented generation (RAG), intelligent agents, document analysis, and custom assistants over an organisation's own data. Paradigm's defining feature is its deployment model: rather than sending data to an external API, LightOn brings the AI to the customer's data. The platform can be installed on-premise, inside a customer VPC, or in fully air-gapped environments, keeping all data within the client's own security perimeter. This makes it suitable for highly sensitive public-sector and regulated enterprise workloads — customers include the Île-de-France region, Safran, Groupama, CNES (French space agency), and the Direction Générale des Finances Publiques. LightOn has trained more than a dozen large language models since 2020 and publishes notable open-source models and libraries (including ModernBERT, BioClinical ModernBERT, and PyLate). Paradigm is model-agnostic and can run open-weight models within the customer's perimeter, so no customer data is used to train shared models. The company holds SOC 2 Type 1 certification and states full GDPR and EU AI Act compliance. Because it is an EU-incorporated, Euronext-listed French company with no US parent, and because its architecture defaults to in-perimeter deployment, LightOn scores very strongly on data sovereignty. The main caveats for the most demanding French public-sector buyers are that its published certification is SOC 2 Type 1 (not Type II) and that ANSSI SecNumCloud qualification appears to be a positioning goal rather than a confirmed, published qualification at the time of writing.
TrustKit Score Breakdown
?88% ExcellentPricing
CustomQuick Facts
Frequently Asked Questions
Is LightOn GDPR compliant?
LightOn has a TrustKit compliance score of 88% (Excellent). Data Residency: Deploys on-premise, in customer VPC, or air-gapped on EU infrastructure, so data never leaves the customer's own security perimeter. Strongest possible residency posture.. Legal Jurisdiction: French SA incorporated in France, listed on Euronext Growth Paris, with no US parent. Fully under EU/French jurisdiction..
Where does LightOn store data?
LightOn hosts data in: EU infrastructure; on-premise, VPC, or air-gapped within customer perimeter. Deploys on-premise, in customer VPC, or air-gapped on EU infrastructure, so data never leaves the customer's own security perimeter. Strongest possible residency posture.
Does LightOn train on user data?
LightOn: No training on customer data; in-perimeter deployment keeps data isolated. In-perimeter deployment means no customer data is sent out or used to train shared models, and retention is governed by the customer's own infrastructure. Scored 4 rather than 5 as public DPA/retention-control documentation is limited.
What certifications does LightOn hold?
LightOn holds: SOC 2 Type 1. Holds SOC 2 Type 1. ISO 27001 and SOC 2 Type II are not confirmed in published sources, and ANSSI SecNumCloud appears to be a positioning goal rather than a confirmed qualification.
Compare LightOn With
Similar Tools
Related Articles
ChatGPT vs Claude: Which Is Better for EU Compliance in 2026?
A detailed comparison of OpenAI's ChatGPT and Anthropic's Claude across data residency, GDPR compliance, certifications, and regulatory suitability for European businesses.
8 min read
GuidesThe 15 Best GDPR-Compliant AI Tools for European Businesses (2026)
Our curated list of the most compliance-friendly AI tools available to EU businesses, rated across data residency, certifications, and regulatory suitability.
12 min read
GuidesSovereign AI in Europe: The Complete Guide to EU-Only AI Platforms
A comprehensive guide to AI platforms that keep data entirely within EU jurisdiction \u2014 no CLOUD Act exposure, no transatlantic data transfers, no compliance gaps.
9 min read