Security

Built for sensitive professional work

Lampi is designed for teams working with confidential company data, financial documents, client information, internal knowledge, and sensitive workflows.

From infrastructure to model selection, access control, agent behavior, and approvals, Lampi is built so teams can use AI agents without losing control over their data or processes.

Infrastructure and models

Choose where your data and intelligence run.

Data residency

Infrastructure and hosting

By default, hosting is in France and the EU. 🇫🇷 🇪🇺

  • Deployment outside Europe is available on request.
  • Private deployment options are available for sensitive use cases, including VPC, dedicated infrastructure, and on-premises or offline configurations.

Model control

Flexible LLM selection

Lampi gives you direct access to leading models, including OpenAI, Anthropic, Mistral, Gemini, DeepSeek, and Kimi, with model availability in France, Europe, and the United States.

  • Open-source model hosting solutions are supported for organizations with specific sovereignty, confidentiality, or compliance requirements.
Your data stays yours

No model training on your data

Your prompts, documents, files, outputs, emails, and internal knowledge are not used to train AI models.

Lampi is designed around strict data handling principles, including zero-retention configurations, controlled model routing, and deployment options that limit how customer data is processed.

Your data is used to perform the work you ask Lampi to do — not to improve third-party models.

Access and permissioning

Enterprise controls at every layer.

Lampi is built with enterprise security controls for sensitive workflows—from authentication and encryption to source-level permissions and approval rights.

Enterprise-grade security

Lampi protects customer data with AES-256 encryption at rest and TLS 1.3 in transit. The platform runs by default on a segmented Microsoft Azure / AKS architecture in France, with internal services private by design. It combines SSO, MFA, RBAC, least-privilege access, WAF/API gateway controls, audit logging, vulnerability monitoring, and other state-of-the-art enterprise security measures across infrastructure, application, and AI workflows.

Role-based access

Admins can assign roles to team users based on their responsibilities and the sensitivity of the data they should access. Roles can control access to data sources, workspace areas, agents, features, administrative settings, and approval rights—separating who can view sensitive material, configure workflows, manage integrations, or approve actions.

Granular data selection

Lampi does not need unrestricted access to your systems. Teams can control which sources Lampi can use, including specific drives, folders, files, inboxes, calendars, or connected applications. Access can be scoped to the exact materials relevant to each team or workflow.

Control for proactive agents

Automation with clear boundaries.

Proactive agents need strong boundaries. Lampi is built so agents operate only within the context, permissions, and workflow rules defined by your organization.

Agents can be limited by approved sources, allowed actions, trigger rules, user roles, and approval requirements.

01

Approved sources only

Each routine can be scoped to specific inboxes, folders, calendars, files, applications, or knowledge sources. Lampi does not need broad access when a workflow only requires selected context.

02

Approved triggers

Routines can start from approved signals such as a new email, updated file, upcoming meeting, recurring schedule, or workflow event. Rules define what should start a run, what should be ignored, and when Lampi should ask first.

03

Human approval before sensitive actions

Lampi can prepare work automatically, but external emails, file changes, calendar changes, irreversible actions, and other sensitive workflow steps require human approval unless configured otherwise by the client.

04

Strict agent behavior controls

AI agents operate within defined scopes, permissions, and workflow instructions. They retrieve, reason, draft, analyze, and prepare work according to the boundaries set for each task or routine.

05

Run history and auditability

Every routine keeps a history of what ran, which output was created, and what happened next—giving teams visibility into proactive work and the context behind each result.

06

Pause or edit anytime

Routines can be paused, edited, narrowed, or expanded as workflows evolve. Teams can adjust trigger rules, source scope, output format, delivery channel, and approval requirements over time.

FAQ

Security questions, answered.

Talk to our team for deployment-specific security, infrastructure, or governance requirements.

Your environment. Your controls.

Discuss your security requirements with our team.

Talk to our team