Security & privacy

Your data never leaves your own server

Lonieta is self-hosted by design, not as an add-on option. That's what makes it a fit for healthcare, finance, legal, public sector and any EU business under GDPR that can't put customer data in someone else's cloud.

Lonieta runs entirely on your own server — not in Lonieta's cloud, not in a third-party data centre chosen by us. There is no version of Lonieta where your customer data is processed anywhere other than the infrastructure you control. That single architectural choice is what separates Lonieta from every cloud-only customer success platform, which at best offers a regional data centre (still their cloud, not yours).

Self-hosted, not "your region of our cloud"

Many vendors describe an EU data centre as a privacy feature. That's a real improvement over a US-only cloud, but it's still the vendor's infrastructure, under the vendor's operational control, reachable if the vendor is breached. With Lonieta, there is no vendor cloud in the picture at all: the application, the database and every customer record live on a server you own or lease and administer yourself.

What that means for regulated industries

For healthcare organisations handling patient-adjacent data, financial and legal firms with strict client confidentiality obligations, public-sector bodies, and any EU company that has decided customer data simply should not leave the building — self-hosting removes an entire category of vendor-risk questions. There's no data processing agreement to negotiate for a sub-processor's cloud, because there is no sub-processor holding your customer data.

Access control & audit

Two-factor authentication (2FA) and role-based permissions are on by default, not a paid add-on. Every critical action — who viewed a customer record, who changed a risk weighting, who exported a report — is written to an audit log, demonstrable in a GDPR audit. Sensitive fields and stored credentials are encrypted at rest.

Privacy-by-design, not privacy-by-policy

Lonieta collects and stores only what the risk model and worklist need: data minimisation and least-privilege access are architectural defaults, not a policy document. No customer data is used to train any shared or third-party AI model — your data trains nothing outside your own installation.

Explainable scoring, human-in-the-loop

Under GDPR, an automated system that makes decisions with legal or similarly significant effect on a person needs a lawful basis and safeguards. Lonieta's risk score is a signalling and prioritisation tool: it flags and ranks, a human decides and acts. Combined with a fully explainable, adjustable scoring model (see how it works), that keeps a human decision-maker in the loop by design, not as an afterthought.

What you're responsible for, what Lonieta is responsible for

Because Lonieta runs on infrastructure you control, your organisation remains the data controller and operates the server (or has it operated on your behalf, e.g. by your own IT provider). Lonieta is responsible for the security of the software itself: secure defaults, encrypted storage of sensitive fields, and a straightforward, well-documented installer so that running it securely doesn't require a dedicated security team.

Frequently asked questions

Does any customer data ever leave my own server?

No. Lonieta is self-hosted: the application, database and all customer data run on infrastructure you control. Nothing is sent to Lonieta's own servers or any third-party cloud.

Is Lonieta GDPR-compliant?

Lonieta is built privacy-by-design: data minimisation, least-privilege access, 2FA, audit logging and encryption of sensitive fields by default. Because you host it yourself, you remain in full control of where the data is and who can access it, which simplifies your own GDPR accountability considerably compared to a cloud-only vendor.

How is this different from a vendor's "EU data centre" option?

An EU data centre is still the vendor's cloud, operated by the vendor. Lonieta has no cloud in the picture at all — the server is yours, whether that's on-premises hardware or a VM you rent and administer.

Does Lonieta use my customer data to train AI models?

No. No customer data is used to train any shared or third-party AI model. Your data stays inside your own installation.

Talk to us about your compliance requirements

Healthcare, finance, legal or public sector — tell us what you need to satisfy and we'll tell you honestly whether Lonieta fits.

Talk to us See how it works