Security & compliance

Lector was built for organisations where data protection is not optional — it is a legal obligation. Whether in our European cloud, hybrid, or fully on-premise in your own network: here you'll find everything you need to know.

Security

Lector Cloud: infrastructure & hosting

  • European data centres (OVHcloud, Germany/France) – ISO 27001 and BSI C5 Type 2 certified

  • No data transfer outside the EU

  • Kubernetes-based infrastructure with automated deployment

  • Redundant systems and automatic failover

  • AI models hosted exclusively in Europe (OVHcloud, Google Vertex AI, Microsoft Azure, Scaleway) – all providers ISO 27001 certified

Encryption & data protection

  • TLS-encrypted communication (in transit)

  • AES-256 encryption of stored data (at rest)

  • GDPR compliant data processing

  • Data processing agreement (DPA) and
    technical and organisational measures (TOMs) available

  • No use of your data for model training, no storage by the AI providers

Access control

  • Role-based access control (RBAC)

  • Single sign-on (SSO) via Keycloak

  • Audit logging of all security-relevant actions

  • Least privilege principle

Certifications & standards

  • ISO 27001: certification in preparation (planned for autumn 2026)

  • GDPR compliant operations since the company was founded

  • Information security management system (ISMS) established in line with ISO 27001

  • Regular internal security reviews; external penetration tests in preparation

Deployment

Options foroperating models

For maximum control we offer hybrid and on-premise deployment alongside our cloud solution.

Cloud

Start instantly, scale instantly

Use the full power of Lector as SaaS, always up to date.

  • Fast onboarding
  • Access to the latest LLMs
  • Standard import/export APIs
  • Highly scalable

Usage-based pricing

Try it free

Hybrid

The best of both worlds

Use the power of state-of-the-art LLMs from the cloud within your own infrastructure.

  • Use AI models from the cloud
  • Data stays on customer servers
  • Flexible architecture & scaling
  • The ideal balance of performance & data protection

Custom pricing

Get in touch

On-Premise

Full control, full sovereignty

Run Lector in your own network with maximum data sovereignty.

  • The highest level of data protection
  • Scalable infrastructure
  • Flexible model adaptation to customer needs
  • Custom integrations

Custom pricing

Get in touch

Frequently asked

Data protection questions

In the Lector Cloud, the platform runs on OVHcloud infrastructure in Europe (Germany/France). AI processing via Google Vertex AI and Microsoft Azure also takes place on European servers — the data is only there for the duration of processing and is deleted immediately afterwards. You decide how long Lector retains your documents. With hybrid or on-premise deployment, your data stays on your own servers.

No. The AI models use your data for processing only; with models from the cloud, it is deleted there immediately afterwards.

TLS encryption in transit, AES-256 at rest, role-based access control, single sign-on via Keycloak and audit logging of all security-relevant actions — on redundant systems with automatic failover.

Yes. The data processing agreement including technical and organisational measures, the EU AI Act statement and further documents are in the Legal Center.

Yes — fully on-premise in your own network, including the platform and the AI models, or hybrid (your data stays with you, the AI models come from the cloud). The deployment options are described above.

Evidence

Documented,not just claimed.

The key documents for data-protection and IT-security reviews are ready in the Legal Center – no request, no waiting.

EU AI Act: minimal risk

Classifying and reading documents falls under recital 53 of the AI Act into the minimal-risk category – no high-risk obligations. Our assessment is there to read.

Read the assessment →

No training on your data – documented

For every AI provider we use – Google Vertex AI, Microsoft Azure OpenAI, OVHcloud, Scaleway – we document the no-training commitment individually.

View the evidence →

DPA, TOMs and sub-processors

Data processing agreement under Art. 28 GDPR with a description of the processing, the TOM checklist and the list of approved sub-processors.

Open the DPA →

Take the load off your
document processes

Get to know Lector — in a personal demo or straight away in a free trial.