Your trust boundary is the design constraint

Most managed search products have one answer to “where does my data live”: in the vendor’s cloud. Lucenia is built the other way around. Four deployment models, one platform, one API — and in every one of them, your data stays inside your trust boundary.

deployment models

From managed cloud to disconnected enclave

cloud

Lucenia Cloud

Fully managed — provisioning, scaling, patching, uptime. Your data remains inside your trust boundary.

byoc

Your VPC

AWS, GCP, or Azure. The platform runs in your cloud account; we operate it. Data never leaves your perimeter.

self-hosted

Your metal

Full platform on infrastructure you control. Tarball, Docker, Helm/Kubernetes, Windows.

air-gapped

No internet

No external endpoints, no egress required to operate. Built for disconnected and classified enclaves.

YOUR TRUST BOUNDARY lucenia cluster data indexes queries results audit logs no egress cloud byoc self-hosted air-gapped we operate it your VPC, we operate you operate no internet who operates the infrastructure changes — where the data lives does not
security controls

What your security team will ask for

AreaDetail
CryptographyFIPS 140-2/3 validated module support, configured at the cluster level · TLS on transport and REST layers
Access controlrole-based, down to index, document, and field level
Multi-tenancytenant isolation for shared clusters serving multiple programs or teams
AuthenticationLDAP · Active Directory · SAML · OpenID Connect · client certificates · Kerberos
Auditaccess and query audit trails, configurable by category and scope
Isolationair-gap capable — no external endpoints, no telemetry, no egress required to operate
Resiliencesnapshot/restore to object storage · cross-cluster replication for DR topologies
Supply chainApache 2.0 open core — the code your accreditors can read
why it matters

One system to accredit, not four

Every system that touches sensitive data carries its own security review, accreditation package, and sustainment burden. A conventional retrieval stack — search engine, vector database, spatial database, and the integration code between them — multiplies that burden by four and spreads the data across four copies.

Consolidating retrieval into one engine is a security decision as much as an architectural one: fewer copies to protect, fewer systems to authorize, one audit trail that covers the whole query path.

Put your security team in the room

The fastest evaluations are the ones where security and engineering hear the same answers at the same time.