Back
Tech 5 min read - 28 Sep. 26 - Benjamin Drighès

Loomi, Odealim's AI assistant: a Claude base, hosted in Europe and secured for business needs

Odealim, the leading French specialist in insurance brokerage and property finance, has approximately 1,600 employees. The group entrusted Galadrim with the construction of Loomi, a general-purpose conversational assistant open to all work topics for its teams, with deployment having started in September 2026.
A large proportion of employees handle named files daily, and the group's rule dictates that this data must remain within its perimeter. Market assistants therefore remain closed to those who would use them the most, i.e. managers and sales staff, whose job involves processing client files.
Addressing this constraint requires deciding where the model runs, what the assistant is allowed to consult, who can read a conversation, and how the company controls consumption. These four questions structured Loomi's design.
« Right from the start, I wanted two things that are often presented as incompatible: a level of security commensurate with the data we handle, and an experience as seamless as that of consumer assistants. Loomi delivers both, because security was designed into the architecture rather than added as a constraint for the user. »
Richard Thibault, CIO and Odealim Comex member

1. Dedicated infrastructure and a model that remains in Europe

The application, its database, its connectors, its memory, its usage counter and its observability run within Odealim's infrastructure, hosted in Europe. Only two flows exit this perimeter: the model call and web search.
Figure 1: Loomi Infrastructure
The model is Claude, called via Amazon Bedrock, and this point made the project possible. Bedrock exposes Anthropic's models on European inference profiles, and the application only offers those. A request leaves the backend, is processed in the region, then returns, isolated from any service outside Europe and any training.
The call to Anthropic's Messages API is direct, which provides access to deferred tool loading, prompt caching on system blocks, and server-side validated structured outputs, and leaves one less component in the prompt path.
Each model occupies the role where it is best placed:
  • Conversation Titling: Claude Haiku 4.5
  • Conversation and Tool Calls: Claude Sonnet 5
  • Long Tasks, at the user's request: Claude Opus 4.8
Web search is the second outgoing flow. It relies on an independent European search index, whose data remains under European Union jurisdiction, and the queries it receives are those formulated by the model, excluding conversation content.
Supervision follows the same rule. Traces and logs remain on the group's infrastructure and describe the form of exchanges, without their content.

2. Connectors aligned with user rights

Loomi accesses Google Workspace, the intranet, the contract management tool, and the ticket tracking tool. The model itself chooses which tools to call, and it chains them together in a single response when a question involves multiple sources.
These connectors obey a single rule, according to which Loomi only sees what the user would have seen themselves. For services that allow it, each user connects their own account via OAuth, and their token accompanies each call. In the absence of a token, the tool responds that the account needs to be connected, and the connector remains deactivated when the user's account is unknown to the remote service. Connection tokens are encrypted like the rest of the user's data.
Connectors operate in read-only mode. This limit is part of the protections against prompt injection, as a document or web page could contain instructions intended for the model.
Adaptation to the company is achieved through skills, reusable instructions such as a procedure, a letter template, or the house style, created by administrators. For the model, these skills are read-only, which protects them from prompt injection originating from a document.

3. Encrypted conversations per user, shared at their initiative

Everything a user writes, uploads, or receives is encrypted with their own unique key, including messages, documents, tool results, and memory, so that access to the database or a backup only yields encrypted data.
Figure 2: Access to Encrypted Conversations
Sharing with an administrator stems from this choice. An administrator is unable to list a user's conversations, as this list would reveal how many they have and at what times. Therefore, sharing always originates from the owner, who chooses the conversation, the recipient, and a duration, with revocation possible at any time. An ephemeral mode completes the system: the conversation remains outside the database, and memory access is closed for both reading and writing.
Memory is what adapts Loomi to each individual. It retains what the user teaches it about their job and preferences, with four tools that the model itself calls to save, read, search, and forget, and a panel where each user can view, delete, export, or import their entries. Persistent memory is also an attack surface, because an instruction hidden in a document dies with the conversation, whereas an instruction passed into memory acts in all subsequent ones. Therefore, protections against prompt injection frame memory writing, and the user retains control over what enters it from their panel.

4. Controlled consumption per user

Odealim's management wanted to avoid consumption excesses. Each model call and web search is attributed to the person who initiated it, a monthly budget is checked before each response, each person tracks their consumption on their page, and an exemption can be granted upon request. Usage indicators are aggregated, with the content of exchanges remaining beyond the employer's reach.

Long-term support

Loomi's value depends on its actual usage. The work commencing involves making it known, embedding it into the teams' daily routine, and evolving it based on user feedback. A Product Manager and AI Lead duo accompanies Odealim through this phase, along with the group's internal communication, an assistant that explains its own operation, and feedback collected from the interface then processed within a few days. This short loop is the best argument for adoption against generic assistants, as what an employee requests can genuinely be integrated.

FAQ

Loomi in four figures

  • 1,600 employees, a large proportion of whom are in contact with client data
  • 100% of content encrypted with a key per user
  • A few months from scoping to production, a few days for user feedback implementation

Do you want support to launch your digital project?

Submit your project now