Skip to main content

Security & Trust Center

Security is our Foundation

Built for the regulated tender workflows our customers run. Honest about where data lives, what we use, and what we don't do.

Data Residency

Production runs on Google Cloud in europe-west1 (Belgium). For Australian customers a dedicated stack in australia-southeast1 (Sydney) is available on request: documents, vector embeddings, application database, and audit logs stay in Sydney. AI inference currently uses Google's global Gemini endpoint pending regional Pro-model deployment, and Bid Library documents are also indexed in a document store in Google's Gemini API with no regional commitment.

Google Cloud's engineering blog published a technical write-up of this architecture: running a global tender platform on AlloyDB and MCP.

No Foundation-Model Training

Customer documents are sent to Google Gemini for analysis only. Per Google's Generative AI terms, paid-tier prompts and responses are not used to train Google's foundation models. We don't send documents to any other AI provider.

Encryption

TLS in transit. Encryption at rest provided by Google Cloud (AES-256) for AlloyDB and Cloud Storage. The Australian deployment's database additionally uses customer-managed encryption keys (CMEK) via Cloud KMS, and connects with IAM-authenticated short-lived tokens rather than a password.

How We Handle Your Data

What We Store

  • Account details (email, name, company) in AlloyDB
  • Analysis results, drafts, and metadata
  • Billing records (Stripe customer + subscription IDs only, never card numbers)
  • Uploaded documents in Google Cloud Storage, encrypted at rest

What We Never Do

  • Send your documents to a foundation-model provider for training
  • Sell or share customer data with third parties for marketing
  • Co-mingle one customer's Bid Library with another's
  • Retain documents indefinitely after account deletion

Application-Layer Controls

Live in production today. Nothing on this list is roadmap.

  • Workspace roles (owner, admin, editor, viewer), and a sign-off that needs an approver other than the person asking
  • Audit logging of user actions and document access, with daily anomaly alerts
  • Customer-defined retention: auto-purge after the number of days you set
  • Workspace export: one archive of members, tender records and the audit trail
  • Draft version history with one-click restore
  • Automated database backups with point-in-time recovery
  • Email alerts on production errors and downtime
  • Login brute-force protection: per-IP and per-account rate limits with lockout
  • Inbound email ingestion checks DMARC, or SPF or DKIM, against sender spoofing

Policy pack available on request: shared responsibility model, retention policy, deletion SLA, and service levels.

Security FAQ

Compliance Posture

We're a small team. We'd rather be honest about where we are than claim badges we haven't earned.

GDPR aligned

Personal data handling, lawful basis, data subject rights, and EU residency.

Inheriting Google Cloud's certifications

Our hosting provider holds ISO 27001, ISO 27017/27018, SOC 2/3, PCI DSS, and others. These cover the underlying infrastructure layer; the application layer is our responsibility.

Architecture published on the Google Cloud blog

In September 2026 the Google Cloud blog published how Lucius runs on AlloyDB for PostgreSQL: two regional database clusters (the Australian one under customer-managed keys), least-privilege database access for our operations agent, and vector search inside the database. Google reviewed the piece before publication. It describes our architecture; it is not a security audit.

Container vulnerability scanning in CI

Every push to the backend runs a Trivy scan of the code and its dependencies, which fails on high and critical CVEs that have a fix. It runs beside the deploy rather than blocking it.

Secret scanning and Cloud Armor

gitleaks in CI and as a pre-commit hook. Cloud Armor edge rules block scanner traffic and rate-limit per IP.

Azure Marketplace listing, co-sell ready

Lucius AI passed Microsoft's commercial marketplace certification and is listed on Azure Marketplace, alongside an approved Google Cloud Marketplace listing. As of August 2026 the solution is also co-sell ready: Microsoft validated our customer materials and lists Lucius in its sellers' internal solution directory. Marketplace certification reviews the vendor, the offer and its claims; it is not a security audit, so we list it here as a diligence signal, not a certificate.

Cyber Essentials: in preparation

The cloud-side readiness work is done; the device and account checks and the certification itself are still to do. We will update this page when it is granted, not before.

Continuous monitoring against SOC 2 and ISO 27001 frameworks

As of July 2026, our EU cloud environment is monitored around the clock against the SOC 2 (2017 Trust Services Criteria) and ISO/IEC 27001:2022 control frameworks via Google Cloud Security Command Center, with automated misconfiguration detection and evidence collection. Security reviewers can request current evidence on specific controls.

SOC 2 / ISO 27001 certification: not yet

Continuous monitoring is not a certificate. Independent audits are on the roadmap as the team grows, and this page will say "certified" only when an auditor does. In the meantime we're happy to walk procurement teams through our setup, with evidence, over a call.

Sub-Processors

ProviderPurposeLocationData Handled
Google Cloud PlatformCompute (Cloud Run), database (AlloyDB), object storage (GCS), KMS, Vertex AI Gemini endpointeurope-west1 (Belgium) primary; australia-southeast1 for AU customer data at rest; Vertex AI global endpoint for inferenceEncrypted documents, application database, user metadata. Inference requests transit to Google's nearest available region for the chosen Gemini model
Google Gemini APIDocument analysis (extraction, compliance, drafting), embeddings, and a per-company document store for Bid Library documentsVertex AI global Gemini endpoint and Google AI Studio; no regional pinning yetDocument text sent at request time, which Google may cache, encrypted and per project, for up to 24 hours; Bid Library documents kept in the company's document store until deleted; not used to train Google's foundation models per Google's terms for paid use
StripePayment processingEU (Dublin) + globalCustomer billing details and card data, handled by Stripe; we never see card numbers
ResendTransactional email deliveryEU/USEmail addresses and message content for product notifications
SentryError tracking and performance monitoringEU (Frankfurt, de.sentry.io)Stack traces, request paths, user IDs (no document content)
PostHogProduct analytics (frontend usage)US (PostHog Cloud US, reached through a first-party proxy)Anonymised event data on UI interactions; no document content
Google Analytics 4Website analyticsGoogle (global)Page views and events on the website, some relayed from our server; no document content
Microsoft Graph, Slack, Google DriveIntegrations a workspace connects: SharePoint import, Slack alerts, Drive file pickerThe provider's own regionsOnly what the connected integration reads or posts: the files you pick or import, the alerts you send

Have a security or procurement question? contact@ailucius.com

Found a vulnerability? Email the same address with details. Reports are read by the founder, acknowledged quickly, and researchers who want credit get it.