Infrastructure we control
lunos.tech and api.lunos.tech run as two independently deployable sites on infrastructure Lunos actually controls — not US cloud infrastructure. That's a deliberate architecture decision, not an afterthought — the project's own site is a live, checkable demonstration of the sovereignty pitch it makes to its users.
Security posture
Both sites are HTTPS-only. The API's CORS policy is locked down to the site's own origin rather than left wide-open, and every request goes through standard input validation before it's persisted. There's no reverse proxy merging the two origins together — the marketing site and the API stay independently deployable and independently auditable.
What we don't collect
There are no user accounts, no login, and no personalization. The only data the site captures is what a visitor explicitly submits through the contact form — an email address and a short note about what they're evaluating Lunos for.
Who this is for
This matters most to EU public-sector integrators and GovTech/civic-tech developers, and to EU regulated-enterprise engineering teams for whom US-hosted developer tooling is a procurement blocker. If sovereignty is a requirement in your own evaluation criteria, this page is meant to be checked, not taken on faith.