Compliance

Sovereignty & Compliance

lunos.tech runs on self-hosted EU infrastructure — the same sovereignty guarantee the project ships to its users.

Infrastructure we control

lunos.tech and api.lunos.tech run as two independently deployable sites on infrastructure Lunos actually controls — not US cloud infrastructure. That's a deliberate architecture decision, not an afterthought — the project's own site is a live, checkable demonstration of the sovereignty pitch it makes to its users.

Security posture

Both sites are HTTPS-only. The API's CORS policy is locked down to the site's own origin rather than left wide-open, and every request goes through standard input validation before it's persisted. There's no reverse proxy merging the two origins together — the marketing site and the API stay independently deployable and independently auditable.

What we don't collect

There are no user accounts, no login, and no personalization. The only data the site captures is what a visitor explicitly submits through the contact form — an email address and a short note about what they're evaluating Lunos for.

Who this is for

This matters most to EU public-sector integrators and GovTech/civic-tech developers, and to EU regulated-enterprise engineering teams for whom US-hosted developer tooling is a procurement blocker. If sovereignty is a requirement in your own evaluation criteria, this page is meant to be checked, not taken on faith.

lunos — an EU-sovereign fork of opencode · lunos.techLicense