LOONAR

Industrial-grade security standards.

Security is a core feature, not an afterthought. Loonar is built to protect sensitive commercial documents so you can use it with confidence and peace of mind.

Our security approach

  1. Zero Data Retention with our AI providers

    The AI model providers we use operate under Zero Data Retention terms: prompts and outputs are processed to generate the response and then discarded, never kept by the provider.

  2. No AI training on customer data

    Our customers' data belongs to them and is never used to train AI models.

  3. Flexible hosting

    Deployment adapts to your governance requirements, for example, deploy inside your own cloud environment.

  4. EU data residency by default

    Customer data is stored and processed exclusively in EU regions, in compliance with GDPR.

  5. Tenant isolation

    Your data and AI outputs never leave your tenant and are never shared with other customers or third parties.

  6. Certified foundations

    Loonar runs on certified infrastructure, Google Cloud and AWS (ISO 27001, SOC 2, EU-U.S. DPF).

How we handle your data

  1. Upload & secure storage

    RFQs, proposals and attachments are uploaded and stored in encrypted storage inside your tenant.

  2. Data processing inside your environment

    Indexing and search/analysis processing happen within your tenant environment.

  3. AI processing with Zero Data Retention

    When AI is used, requests are transmitted over encrypted connections and providers are configured for Zero Data Retention, with no storage or reuse of prompts or outputs for model training or improvement.

  4. Outputs stay in your tenant

    Results are stored only inside Loonar within your tenant. Upon termination, data can be exported and deleted from production systems, with backups handled through standard retention cycles.

FAQ

Where can I find your Data Processing Agreement?

It is published at loonar-ai.com/dpa, together with our Cybersecurity Appendix. You do not need to ask us for it or sign an NDA to read it.

Can we run a security review or audit?

Yes. Section 9 (Audit & Inspection) of the DPA sets out the process and the conditions.

Which sub-processors do you use?

Appendix C of the DPA lists the current sub-processors. Section 4.2 (Sub-processor changes) covers the notice you get and your right to object.

What happens to our data when the service ends?

Section 8 (Return and Deletion of Data) of the DPA sets out the export and deletion steps, and how backups are handled.

Is our data used to train AI models?

No. Customer data, prompts and outputs are never used to train, fine-tune or improve AI models, by Loonar or by our third-party providers. Where AI is used, providers are configured for Zero Data Retention, so prompts and outputs are not kept after processing.

Where is our data stored and processed?

In EU regions by default, handled in line with EU GDPR requirements. Your documents and outputs stay inside your tenant and are never shared with other customers.

Reading RFQ documents was never your team’s job. Winning them is.

Our security documentation is available on request, so your team can start reviewing before you upload a single document.