Graded F on resilience. In Vannus's assessment it has not disclosed which model it runs — a thin layer over someone else's foundation model.
AI assistant from Proton, built by the team behind Proton Mail and Proton VPN. The page footer names 'Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland'. Vendor states "All conversations with Lumo are stored with zero-access encryption, so no one (not even Proton) can access them", that Lumo "Does not log your chats", that "we never use your data to train AI models", tha
Not disclosed. Proton Lumo does not publish which model it runs, so this criterion is excluded and the grade rests on what we could verify. We say so rather than guess.
This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This measures who can compel your data. A tool can score modestly on one and strongly on the other, and many do.
The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.
Vannus grades Proton Lumo against nine dimensions of trust — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →