"Gen AI With The Control You Need."
Paradigm is an enterprise GenAI platform from LightOn for private LLMs, enterprise search, RAG, document analysis, and knowledge work. The platform can be operated in a sovereign European cloud, private cloud, on-premises, or air-gapped environment.
LightOn Paradigm
Gen AI With The Control You Need.
Location: France ⓘ LightOn SA, 2 rue de la Bourse, 75002 Paris, France.
Free entry for API tests and initial OCR, extraction, and retrieval applications. Subscription API Business API usage for productive teams with business support and usage-based scaling.
Paradigm SaaS Seat-based enterprise AI with chat, RAG, enterprise search, permissions, and integrations.
Enterprise Custom deployment with SLA, SSO, SCIM, governance, private cloud, or on-premises. Other On-Premise / Air Gap Operation entirely within your own infrastructure for classified or regulated data.
Hybrid Deployment Local data storage combined with sovereign European GPU resources.
Professional Services Implementation, data connectivity, model integration, retrieval optimization, and customer-specific use cases.
Target audience
LightOn Paradigm is aimed at large enterprises, public institutions, government agencies, industrial companies, insurers, banks, and organizations with sensitive documents, high compliance requirements, and a need for sovereign AI.
Outstanding features
Paradigm combines enterprise search, RAG, multimodal document analysis, proprietary or bring-your-own LLMs, rights management, and various deployment models. LightOnOCR can also process documents within your own infrastructure.
Main application areas
Typical use cases include internal knowledge search, document analysis, contract and compliance assistance, research knowledge, technical documentation, government knowledge, engineering documents, and AI-supported knowledge work.
Usage & notes
For productive use, companies should define data classification, role models, indexing rules, source systems, model selection, and audit requirements in advance. Where a high level of protection is required, on-premise or an isolated private cloud is preferable to general SaaS operation.
Hosting & Data
1) On-prem / local hosting
Meaning: The company operates the solution on its own hardware or within its own infrastructure. In the strictest sense, not only the application runs locally, but ideally the model as well.
2) Private cloud / data center
Meaning: The solution runs in a dedicated or more clearly separated cloud environment, often with a hosting provider or hyperscaler, but in a German data center or in a particularly controlled environment.
3) EU SaaS / managed
Meaning: The provider operates the solution itself as a service. The company uses the tool as a ready-made cloud service, ideally with EU data residency.
4) Hybrid
Meaning: One part of the processing remains internal / local / in a private cloud, while another part runs in an external cloud or EU SaaS.
5) AVV / DPA
Meaning: This is the data processing agreement or Data Processing Addendum. It governs that the provider processes personal data on behalf of the customer and is bound by the customer's instructions.
6) No training
Meaning: The provider does not use your prompts, uploads, attachments, chat histories, or outputs for training or improving the general model — ideally excluded by contract.
7) Open-source / transparency path
Meaning: There is a path toward greater technical transparency and sovereignty, for example through:
- open models
- documented components
- self-hostable parts
- traceable architecture
- export / switching options
| On-prem / local hosting | ✅ |
| Private cloud / data center | ✅ |
| EU SaaS / Managed | ✅ |
| Hybrid | ✅ |
| DPA / AVV | ✅ |
| No training on customer data | ⚠️ |
| Open source / transparency path | ⚠️ |
On-Prem / local hosting: covered
The product page explicitly mentions 'On-Premise' as well as 'Both compute and data on your infrastructure. Air-gap capable'. This clearly documents local hosting on the customer's own infrastructure.
Private cloud / data center: covered
Private/segregated cloud is clearly evidenced: the website mentions hybrid with 'sovereign European cloud GPUs' and other pages mention private cloud or cloud prive as a deployment option.
EU SaaS / Managed: covered
The deployment page describes a SaaS offering as 'Fully Sovereign, Fully Managed' and 'Entirely hosted on sovereign European cloud infrastructure'. This at least clearly addresses EU data residency at the level of European infrastructure.
Hybrid: covered
Hybrid is explicitly mentioned: 'Data stays on-premise while sovereign European cloud GPUs accelerate inference. Full performance with full data residency.'
DPA / DPA: covered
The Terms explicitly define a 'Data Processing Agreement (DPA)' and state that LightOn processes personal data on behalf of the customer in accordance with the DPA concluded with the customer.
No training: partial
Positive: The Terms explicitly state 'No Training' for 'Feedback Content' routed to LightOn and that it is not used to train, retrain, or fine-tune foundational AI models. However, a general, product-wide exclusion covering all prompts, uploads, chat histories, and outputs is not consistently evidenced on the website; the Privacy Policy mentions that online chat data in the support/website context is in part used to improve the chatbot service via machine learning.
Open source / transparency path: partial
There is a transparency/sovereignty path: the website mentions open models/components such as 'Built on ... our open-source ColBERT family', 'Bring your own model. Open-source, commercial, or private' and the Terms state that open-source software components are subject to separate open-source licenses. However, the website does not provide a complete technical disclosure of all Paradigm components.
Data processing
The website describes three main paths relevant for the EU/EEA: On-Premise with data and compute on customer infrastructure, Hybrid with data remaining on-premise and European cloud acceleration for inference, and Managed SaaS on sovereign European cloud infrastructure. From a data protection law perspective, this is supported by the Privacy Policy with information on processing in France or the EU, DPA/SCC/appropriate safeguards for cross-border transfers, and a GDPR compliance page with rights and protective measures.
Conclusion
For a European tool directory, the overall assessment is positive: LightOn documents several EU/EEA-suitable and data-sovereign operating models, especially On-Premise and Hybrid, which open up a straightforward path to GDPR-compliant use throughout the EU/EEA. The biggest open points are the lack of publicly available detail on specific data center locations and the subprocessors list being available only on request, as well as a no-training exclusion that is not fully formulated in general terms for all usage data.
Sources
- https://lighton.ai/deployment-options
- https://lighton.ai/privacy-policy
- https://docs.lighton.ai/en/support-legal/legal-and-compliance/gdpr-compliance
- https://docs.lighton.ai/en/support-legal/legal-and-compliance/privacy-policy
- https://paradigm-academy.lighton.ai/en/support-legal/legal-and-compliance/terms-of-use
- https://lighton.ai/partners-and-white-labelling
- https://lighton.ai/
- https://www.lighton.ai/fr/ready-to-use-interface
| On-prem / local hosting | ✅ |
| Private cloud / data center | ✅ |
| EU SaaS / Managed | ✅ |
| Hybrid | ✅ |
| DPA / AVV | ✅ |
| No training on customer data | ⚠️ |
| Open source / transparency path | ⚠️ |
On-Prem / local hosting: covered
The product page explicitly mentions 'On-Premise' as well as 'Both compute and data on your infrastructure. Air-gap capable'. This clearly documents local hosting on the customer's own infrastructure.
Private cloud / data center: covered
Private/segregated cloud is clearly evidenced: the website mentions hybrid with 'sovereign European cloud GPUs' and other pages mention private cloud or cloud prive as a deployment option.
EU SaaS / Managed: covered
The deployment page describes a SaaS offering as 'Fully Sovereign, Fully Managed' and 'Entirely hosted on sovereign European cloud infrastructure'. This at least clearly addresses EU data residency at the level of European infrastructure.
Hybrid: covered
Hybrid is explicitly mentioned: 'Data stays on-premise while sovereign European cloud GPUs accelerate inference. Full performance with full data residency.'
DPA / DPA: covered
The Terms explicitly define a 'Data Processing Agreement (DPA)' and state that LightOn processes personal data on behalf of the customer in accordance with the DPA concluded with the customer.
No training: partial
Positive: The Terms explicitly state 'No Training' for 'Feedback Content' routed to LightOn and that it is not used to train, retrain, or fine-tune foundational AI models. However, a general, product-wide exclusion covering all prompts, uploads, chat histories, and outputs is not consistently evidenced on the website; the Privacy Policy mentions that online chat data in the support/website context is in part used to improve the chatbot service via machine learning.
Open source / transparency path: partial
There is a transparency/sovereignty path: the website mentions open models/components such as 'Built on ... our open-source ColBERT family', 'Bring your own model. Open-source, commercial, or private' and the Terms state that open-source software components are subject to separate open-source licenses. However, the website does not provide a complete technical disclosure of all Paradigm components.
Data processing
The website describes three main paths relevant for the EU/EEA: On-Premise with data and compute on customer infrastructure, Hybrid with data remaining on-premise and European cloud acceleration for inference, and Managed SaaS on sovereign European cloud infrastructure. From a data protection law perspective, this is supported by the Privacy Policy with information on processing in France or the EU, DPA/SCC/appropriate safeguards for cross-border transfers, and a GDPR compliance page with rights and protective measures.
Conclusion
For a European tool directory, the overall assessment is positive: LightOn documents several EU/EEA-suitable and data-sovereign operating models, especially On-Premise and Hybrid, which open up a straightforward path to GDPR-compliant use throughout the EU/EEA. The biggest open points are the lack of publicly available detail on specific data center locations and the subprocessors list being available only on request, as well as a no-training exclusion that is not fully formulated in general terms for all usage data.
Sources
- https://lighton.ai/deployment-options
- https://lighton.ai/privacy-policy
- https://docs.lighton.ai/en/support-legal/legal-and-compliance/gdpr-compliance
- https://docs.lighton.ai/en/support-legal/legal-and-compliance/privacy-policy
- https://paradigm-academy.lighton.ai/en/support-legal/legal-and-compliance/terms-of-use
- https://lighton.ai/partners-and-white-labelling
- https://lighton.ai/
- https://www.lighton.ai/fr/ready-to-use-interface
Strengths & weaknesses at a glance
| Strengths | Weaknesses |
|---|---|
| • Very strong sovereignty and on-premises focus | • Strongly enterprise-oriented and usually overkill for individual users |
| • Air-gapped and private cloud options | • Private deployments may require your own infrastructure and GPU capacity |
| • Enterprise search, RAG, OCR, and knowledge work | • An enterprise project is required for full governance features |
| • API, SSO, RBAC, audit logs, and data sources | • Public pricing details for Paradigm are limited |
| • EU-sovereign hosting according to the provider |
Reviews
0 reviews in total
There are no confirmed reviews for this tool yet.
Submit review
Your review will only become visible after email confirmation. This protects the portal against abuse.
Report review
Please select the reason why this review should be checked.
GDPR-compliant usage possible?
LightOn Paradigm can overall be assessed as usable in a GDPR-compliant manner for users in the EU/EEA based on the provider's website, because LightOn explicitly offers on-premise, hybrid, and SaaS operating models with sovereign European cloud infrastructure, and for on-premise it even states that compute and data remain on the customer's infrastructure. In addition, the legal texts refer to GDPR compliance, DPA/AVV agreements with customers, and safeguards for international transfers. The assessment is based on the best available usage path in the EU/EEA, not only a possible standard SaaS setup.
Positive
Positive aspects are the clearly documented deployment options on-premise, hybrid, and SaaS on sovereign European cloud infrastructure. For hybrid, it states that data remains on-premise and only European cloud GPUs are used for inference. In the legal texts, LightOn identifies itself as a data processor for customer data and refers to a DPA/AVV concluded with the customer. In addition, there is a dedicated GDPR compliance page with data subject rights, protective measures, storage limitation, and information on international transfers.
Negative
Negative or limiting is that the specific server/data center location for Paradigm SaaS is not identified down to the country/data center level. The privacy policy only states that most processing directly controlled by LightOn takes place in France or in the EU and that some processing by subprocessors may take place in various locations. According to the website, a complete subprocessor list is only available upon request. Furthermore, an explicit general "no training on any customer content" is not comprehensively documented on the website for every usage scenario; training is explicitly excluded for feedback content transmitted to LightOn, while chat/support data is in some cases mentioned for service improvement or machine learning in the website/support context.
Server location
The website does not name a single specific Paradigm data center. The privacy policy states that most processing directly controlled by LightOn takes place in France or in the EU; further processing by subprocessors may occur in various locations. For the product page, SaaS is described as 'entirely hosted on sovereign European cloud infrastructure', hybrid with 'sovereign European cloud GPUs', and on-premise with data and compute on customer infrastructure.