Now in early access — deploy your first AI agent before lunch. EU-hosted. Credits, not seats.See agents

Security & data at Agents by LaunchCI

Last reviewed May 14, 2026

Agents by LaunchCI is built for European businesses that need AI to work without surrendering control of their data. This page explains how we protect your information — by default, not as an enterprise upgrade.

Where your data lives

Agents by LaunchCI runs on EU-hosted infrastructure. Your prompts, memory, and tool outputs stay within EU jurisdiction. We do not transfer customer data outside the EU as part of normal operation.

Each customer gets an isolated container. Your agent does not share state, memory, or storage with any other business's agent — ever.

What we do with your data

  • We don't train on your content. Your prompts, documents, and agent outputs are never used to train models — ours or any third party's.
  • Persistent memory is yours. Each agent's memory lives in your isolated container. You can review, export, or delete it at any time.
  • No cross-customer use. Knowledge captured by one customer's agent is never used to enrich another's.

“Most AI tools treat your data as fuel for their next model. We treat it as the customer's asset. Period.”

Compliance

  1. GDPR by default. Our standard contract includes a Data Processing Agreement (DPA) compatible with GDPR Article 28.
  2. EU data residency. Primary and backup data both reside in EU regions.
  3. Sub-processor transparency. We publish the list of sub-processors we rely on (LLM providers, hosting, observability) and notify customers in advance of any changes.
  4. Right to deletion. Agent memory, uploaded documents, and account data can be fully deleted on request and on account closure.

Encryption and access controls

In transit

All traffic between your team, your agent, and any connected tool uses TLS 1.2 or higher. Webhooks and integrations use signed, customer-specific credentials.

At rest

Agent memory, uploaded documents, and credentials are encrypted at rest. Encryption keys are managed inside the EU.

Internal access

LCI engineers do not access customer agent content as part of normal operations. Production access is audited and limited to named on-call staff for incident response.

Enterprise: BYOK and self-hosted deployments

Enterprise customers can run agents on their own infrastructure — private cloud, on-prem, or air-gapped — and bring their own LLM key (BYOK). LCI manages the agent layer; you control the compute, the model, and the data boundary. Custom DPAs, SSO, and audit logs are part of the Enterprise package.

Responsible disclosure

If you believe you've found a security issue with LCI Agents, please contact security@launch.ci. We acknowledge reports within two business days and work with you on a coordinated disclosure timeline. We don't pursue good-faith researchers who follow a reasonable process.

Questions about a specific deployment, DPA, or compliance review? Email security@launch.ci and we'll route you to the right person.