Security & Trust
Last updated 2026-10-03
Loúgeon is designed so that AI can do real work without doing anything you haven't allowed. This page describes the controls built into the product. We do not currently claim any third-party certification.
Organization isolation
Every business record carries an organization identifier and is protected by row-level security in the database. Access between organizations is blocked at the database, not only in the interface. Demo data lives in its own separate organization.
Roles and permissions
Each member is an Owner, Admin, Member or Viewer. Viewers can read but never execute. Only Owners and Admins change AI settings, operators, workflows and integrations.
Controlled AI actions
- Operators only propose actions. A single action engine validates each one before it runs.
- Every action is checked against the acting person's role, the organization's policy for that action (Automatic, Approval required or Person only), the subscription and the required integration.
- The AI can never act with more access than the person it acts for.
- Approvals are claimed atomically, so one approval executes once — even if pressed twice at the same moment.
Audit trail
AI actions, approvals and setting changes are written server-side to an audit log that users cannot edit or delete.
Integrations and credentials
Connections to email, calendar and accounting use the provider's own authorization. Tokens are stored server-side and never sent to the browser. Without a connected system, Loúgeon does not send, book or change anything externally — it prepares a task or approval instead.
AI usage controls
Every model call is recorded with provider, model, tokens and estimated cost, and is blocked when a plan or organization spending limit is reached.
Reporting a vulnerability
Email security@lougeon.com. Please give us reasonable time to respond before public disclosure.