The Blog

"Gen AI With The Control You Need."

Paradigm is an enterprise GenAI platform from LightOn for private LLMs, enterprise search, RAG, document analysis, and knowledge work. The platform can be operated in a sovereign European cloud, private cloud, on-premises, or air-gapped environment.
LightOn Paradigm

Gen AI With The Control You Need.

(0)

Your review

Click the stars to start your review.

7.3/10 KIFOX Score – Good

Location: France LightOn SA, 2 rue de la Bourse, 75002 Paris, France.

Automation Chatbot Document analysis Research Job Listings Text generation Knowledge Base
Free LightOn API Starter
Free entry for API tests and initial OCR, extraction, and retrieval applications.
Subscription API Business API usage for productive teams with business support and usage-based scaling.

Paradigm SaaS Seat-based enterprise AI with chat, RAG, enterprise search, permissions, and integrations.

Enterprise Custom deployment with SLA, SSO, SCIM, governance, private cloud, or on-premises.
Other On-Premise / Air Gap Operation entirely within your own infrastructure for classified or regulated data.

Hybrid Deployment Local data storage combined with sovereign European GPU resources.

Professional Services Implementation, data connectivity, model integration, retrieval optimization, and customer-specific use cases.

Target audience

LightOn Paradigm is aimed at large enterprises, public institutions, government agencies, industrial companies, insurers, banks, and organizations with sensitive documents, high compliance requirements, and a need for sovereign AI.

Outstanding features

Paradigm combines enterprise search, RAG, multimodal document analysis, proprietary or bring-your-own LLMs, rights management, and various deployment models. LightOnOCR can also process documents within your own infrastructure.

Main application areas

Typical use cases include internal knowledge search, document analysis, contract and compliance assistance, research knowledge, technical documentation, government knowledge, engineering documents, and AI-supported knowledge work.

Usage & notes

For productive use, companies should define data classification, role models, indexing rules, source systems, model selection, and audit requirements in advance. Where a high level of protection is required, on-premise or an isolated private cloud is preferable to general SaaS operation.

Hosting & Data

✅ = well covered ⚠️ = partial / indirect ❓ = not available / unclear
?

1) On-prem / local hosting
Meaning: The company operates the solution on its own hardware or within its own infrastructure. In the strictest sense, not only the application runs locally, but ideally the model as well.

2) Private cloud / data center
Meaning: The solution runs in a dedicated or more clearly separated cloud environment, often with a hosting provider or hyperscaler, but in a German data center or in a particularly controlled environment.

3) EU SaaS / managed
Meaning: The provider operates the solution itself as a service. The company uses the tool as a ready-made cloud service, ideally with EU data residency.

4) Hybrid
Meaning: One part of the processing remains internal / local / in a private cloud, while another part runs in an external cloud or EU SaaS.

5) AVV / DPA
Meaning: This is the data processing agreement or Data Processing Addendum. It governs that the provider processes personal data on behalf of the customer and is bound by the customer's instructions.

6) No training
Meaning: The provider does not use your prompts, uploads, attachments, chat histories, or outputs for training or improving the general model — ideally excluded by contract.

7) Open-source / transparency path
Meaning: There is a path toward greater technical transparency and sovereignty, for example through:
- open models
- documented components
- self-hostable parts
- traceable architecture
- export / switching options

✅ = well covered ⚠️ = partial / indirect ❓ = not available / unclear
On-prem / local hosting
Private cloud / data center
EU SaaS / Managed
Hybrid
DPA / AVV
No training on customer data ⚠️
Open source / transparency path ⚠️

On-Prem / local hosting: covered

The product page explicitly mentions 'On-Premise' as well as 'Both compute and data on your infrastructure. Air-gap capable'. This clearly documents local hosting on the customer's own infrastructure.

Private cloud / data center: covered

Private/segregated cloud is clearly evidenced: the website mentions hybrid with 'sovereign European cloud GPUs' and other pages mention private cloud or cloud prive as a deployment option.

EU SaaS / Managed: covered

The deployment page describes a SaaS offering as 'Fully Sovereign, Fully Managed' and 'Entirely hosted on sovereign European cloud infrastructure'. This at least clearly addresses EU data residency at the level of European infrastructure.

Hybrid: covered

Hybrid is explicitly mentioned: 'Data stays on-premise while sovereign European cloud GPUs accelerate inference. Full performance with full data residency.'

DPA / DPA: covered

The Terms explicitly define a 'Data Processing Agreement (DPA)' and state that LightOn processes personal data on behalf of the customer in accordance with the DPA concluded with the customer.

No training: partial

Positive: The Terms explicitly state 'No Training' for 'Feedback Content' routed to LightOn and that it is not used to train, retrain, or fine-tune foundational AI models. However, a general, product-wide exclusion covering all prompts, uploads, chat histories, and outputs is not consistently evidenced on the website; the Privacy Policy mentions that online chat data in the support/website context is in part used to improve the chatbot service via machine learning.

Open source / transparency path: partial

There is a transparency/sovereignty path: the website mentions open models/components such as 'Built on ... our open-source ColBERT family', 'Bring your own model. Open-source, commercial, or private' and the Terms state that open-source software components are subject to separate open-source licenses. However, the website does not provide a complete technical disclosure of all Paradigm components.

Data processing

The website describes three main paths relevant for the EU/EEA: On-Premise with data and compute on customer infrastructure, Hybrid with data remaining on-premise and European cloud acceleration for inference, and Managed SaaS on sovereign European cloud infrastructure. From a data protection law perspective, this is supported by the Privacy Policy with information on processing in France or the EU, DPA/SCC/appropriate safeguards for cross-border transfers, and a GDPR compliance page with rights and protective measures.

Conclusion

For a European tool directory, the overall assessment is positive: LightOn documents several EU/EEA-suitable and data-sovereign operating models, especially On-Premise and Hybrid, which open up a straightforward path to GDPR-compliant use throughout the EU/EEA. The biggest open points are the lack of publicly available detail on specific data center locations and the subprocessors list being available only on request, as well as a no-training exclusion that is not fully formulated in general terms for all usage data.

Sources

On-prem / local hosting
Private cloud / data center
EU SaaS / Managed
Hybrid
DPA / AVV
No training on customer data ⚠️
Open source / transparency path ⚠️

On-Prem / local hosting: covered

The product page explicitly mentions 'On-Premise' as well as 'Both compute and data on your infrastructure. Air-gap capable'. This clearly documents local hosting on the customer's own infrastructure.

Private cloud / data center: covered

Private/segregated cloud is clearly evidenced: the website mentions hybrid with 'sovereign European cloud GPUs' and other pages mention private cloud or cloud prive as a deployment option.

EU SaaS / Managed: covered

The deployment page describes a SaaS offering as 'Fully Sovereign, Fully Managed' and 'Entirely hosted on sovereign European cloud infrastructure'. This at least clearly addresses EU data residency at the level of European infrastructure.

Hybrid: covered

Hybrid is explicitly mentioned: 'Data stays on-premise while sovereign European cloud GPUs accelerate inference. Full performance with full data residency.'

DPA / DPA: covered

The Terms explicitly define a 'Data Processing Agreement (DPA)' and state that LightOn processes personal data on behalf of the customer in accordance with the DPA concluded with the customer.

No training: partial

Positive: The Terms explicitly state 'No Training' for 'Feedback Content' routed to LightOn and that it is not used to train, retrain, or fine-tune foundational AI models. However, a general, product-wide exclusion covering all prompts, uploads, chat histories, and outputs is not consistently evidenced on the website; the Privacy Policy mentions that online chat data in the support/website context is in part used to improve the chatbot service via machine learning.

Open source / transparency path: partial

There is a transparency/sovereignty path: the website mentions open models/components such as 'Built on ... our open-source ColBERT family', 'Bring your own model. Open-source, commercial, or private' and the Terms state that open-source software components are subject to separate open-source licenses. However, the website does not provide a complete technical disclosure of all Paradigm components.

Data processing

The website describes three main paths relevant for the EU/EEA: On-Premise with data and compute on customer infrastructure, Hybrid with data remaining on-premise and European cloud acceleration for inference, and Managed SaaS on sovereign European cloud infrastructure. From a data protection law perspective, this is supported by the Privacy Policy with information on processing in France or the EU, DPA/SCC/appropriate safeguards for cross-border transfers, and a GDPR compliance page with rights and protective measures.

Conclusion

For a European tool directory, the overall assessment is positive: LightOn documents several EU/EEA-suitable and data-sovereign operating models, especially On-Premise and Hybrid, which open up a straightforward path to GDPR-compliant use throughout the EU/EEA. The biggest open points are the lack of publicly available detail on specific data center locations and the subprocessors list being available only on request, as well as a no-training exclusion that is not fully formulated in general terms for all usage data.

Sources

Strengths & weaknesses at a glance

Strengths Weaknesses
• Very strong sovereignty and on-premises focus • Strongly enterprise-oriented and usually overkill for individual users
• Air-gapped and private cloud options • Private deployments may require your own infrastructure and GPU capacity
• Enterprise search, RAG, OCR, and knowledge work • An enterprise project is required for full governance features
• API, SSO, RBAC, audit logs, and data sources • Public pricing details for Paradigm are limited
• EU-sovereign hosting according to the provider

Data last updated: 29. June 2026

Reviews

0 reviews in total

(0)
5★ 0.0%
4★ 0.0%
3★ 0.0%
2★ 0.0%
1★ 0.0%

There are no confirmed reviews for this tool yet.