Lurus Code
Lurus Code is an autonomous AI coding agent from the German vendor Lurus GmbH. It plans, implements, tests and reviews code inside VS Code and the command line, with zero data retention and no training on your source code.
What is Lurus Code?
Lurus Code is an autonomous AI coding agent published by Lurus GmbH, a company based in Isernhagen, Germany. It is positioned deliberately against autocomplete tools: rather than suggesting the next line, it examines the relevant project context, plans a change, edits files, runs the intended quality checks and presents the result for review. The agent offers four modes and more than nineteen tools, and supports extended thinking on longer tasks.
Its distinguishing architecture is multi-agent. An orchestrator distributes work across specialised roles, a planner, an explorer and a shell agent, with quality gates between them, so that planning, coding and testing can proceed in parallel on a single assignment. Around that core sit automated code review with HTML and JSON export, security scanning built on four scan skills with CWE mapping, SARIF output, inline diagnostics and generated patches, test generation with TDD workflows, and automatic documentation including Mermaid diagrams and changelogs.
The tool reaches developers through a native VS Code extension offering a chat panel, a diff view, diagnostics and inline editing, and through a CLI installed from npm that covers batch use, CI integration and shell completions. Sessions persist: decisions, architecture and preferences are remembered, and a session can be resumed, recalled, rewound or exported. Extensions include community skills, Model Context Protocol servers, custom agents and rules declared in a LURUS.md file, semantic code indexing backed by retrieval, event hooks across eleven events, and browser automation with Brave Search. A permission system constrains the agent through sandbox boundaries, file guards, command allowlists and a read-only planning mode.
Models are selectable rather than fixed. Alongside Lura, the vendor's own model, the catalogue spans Anthropic, OpenAI and Google models plus open-source options, each labelled with its provider and processing region. The commercial argument throughout is data sovereignty: zero data retention on every route, no training on customer code, and a published processing agreement. The interface itself is available in English and German.
What it does
- Turns a described goal into a planned, implemented and tested code change
- Reviews code changes automatically and exports the result as HTML or JSON
- Scans for vulnerabilities with CWE mapping, SARIF output and generated patches
- Distributes a task across specialised agents coordinated by an orchestrator
- Generates tests and supports test-driven development workflows
- Produces documentation, Mermaid diagrams and changelog entries
- Indexes a codebase for semantic search and carries context across sessions
When to use Lurus Code / When not to
A quick filter to help you decide if Lurus Code is the right fit.
When to use Lurus Code
- European development teams that must document GDPR compliance for every tool in their stack
- Engineering organisations that want per-seat costs removed, since team members are billed at nothing and only real usage is drawn from a shared balance
- Individual developers who work primarily in VS Code or in a terminal
- Platform and DevOps engineers wiring automated review and security scanning into GitHub Actions, GitLab CI, Jenkins or CircleCI
- Security and compliance leads who need the model, the provider and the processing region named before a request is sent
When not to use Lurus Code
- Anyone who needs a mobile app: the product ships only as a VS Code extension, a CLI and a web dashboard
- Developers looking to build on a public REST API, which is not documented anywhere on the site
- Teams that want a permanently free tier, since the only free access is a one-week trial
- Users who need an interface language other than English or German
- Projects that would place the agent inside a safety component or a high-risk AI system, a use the terms expressly exclude
How to use Lurus Code
A typical end-to-end flow, from setup to results.
- Install the command-line client globally from npm with the @scramble-cloud/lurus-code-cli package
- Authenticate once by running the login command
- Start the agent inside a project directory to open a first session
- Alternatively, install the native VS Code extension and work from the chat panel and diff view
- Describe the goal or the task you want carried out
- Let the orchestrator plan the work and distribute it across the specialised agents
- Choose the model route, checking the provider and processing region shown for it
- Review the proposed changes in the diff view and run the security scan
- Create an API key in the dashboard to authenticate headless runs, then supply it through the environment variable, the login flag or the request header
- Wire the CLI into GitHub Actions, GitLab CI, Jenkins or CircleCI for automated review on each change
Pros & Cons
Pros
- An unconditional no-training commitment that the vendor extends to every connected model provider
- Zero data retention applied by default on all model and provider routes
- A German publisher governed by German and EU law, with a data processing agreement published openly
- Team use carries no seat, licence or base fee, with only actual consumption drawn from a shared balance
- The model, the provider and the processing region are disclosed before a route is selected
- A broad model catalogue, including European-hosted open-source options and the vendor's own model
- Included credits exceed the plan price at every tier, from thirty euros of credit on a twenty euro plan
Cons
- No permanently free plan, only a one-week trial available once per person or organisation
- The ISO/IEC 27001 certification and C5 attestation cover the hosting infrastructure, not Lurus GmbH itself
- No certificate number or certifying body is published for the publisher
- No documented public API: the API keys authenticate the client rather than opening an interface
- A young and small company, registered in 2023 and converted to a GmbH only in August 2026
- GitHub and Discord presences are advertised as coming soon, and the GitHub link in the page metadata is dead
- The headline counters on the home page render as zero in the served markup
Pricing & Plans
There is no permanently free plan. Access to the paid tiers is preceded by a one-week free trial, available once per person, company or organisation, and covering the Pro, Pro+ and Ultra tiers. The lowest paid entry point is the Pro plan at EUR 20 per month, quoted exclusive of statutory VAT and including thirty euros of AI credits together with twenty euros of separate Lura credits. Subscriptions renew monthly and may be cancelled at any time without a lock-in commitment, and unused credits do not expire. Team use is billed differently: members cost nothing each, and the organisation funds a shared balance from which only real usage is deducted.
- EUR 20 per month
- including EUR 30 of AI credits and EUR 20 of Lura credits
- with security scanning
- code review
- the plugin system
- custom agents
- the CLI and the VS Code extension
- EUR 60 per month
- including EUR 105 of AI credits and EUR 60 of Lura credits
- adding the GitHub Action for CI/CD security and higher agent limits
- EUR 200 per month
- including EUR 400 of AI credits and EUR 200 of Lura credits
- adding agent teams
- orchestration and priority access to new features
- EUR 0 per member with no seat
- licence or base fee
- funded through a shared balance with per-member budgets and admin policies
- conversion to Team is permanent
Data, GDPR & hosting
A consolidated view of how Lurus Code handles your data.
GDPR overview
The vendor is established in Germany, so the GDPR applies directly and no Article 27 representative is required or named. Concrete measures are published rather than merely asserted: a full data processing agreement is available at /en/dpa/, sub-processors are named in the privacy policy with their corporate identities and addresses and listed again in Annex 2 of the agreement, and changes to that list may be objected to within seven days. Zero data retention is stated as the default on every model route, and training on customer data is excluded. Privacy questions and sub-processor enquiries are directed to a dedicated address. No data protection officer is named, and no minimum age is stated.
Who owns the data?
The terms state that the customer keeps all rights to the content they enter, meaning prompts and source code, and remains responsible for its legality. Lurus GmbH positions itself as a processor under the GDPR while the customer stays the controller, an allocation set out in the data processing agreement published on the site. The vendor undertakes not to store source code beyond the time needed to answer a request, and not to use customer data or code to train AI models. That commitment is stated to bind Lurus and every model provider reached through the product.
Reuse rights
Because the customer retains the rights to the prompts and code they submit, they may reuse the output of their own sessions without seeking permission from Lurus. The vendor's own use of that material is deliberately narrow: context is transmitted only for the duration of the request, only the context the specific request and the selected tools require is sent, and nothing is kept once processing ends. Training on customer data or source code is excluded, and the site extends that exclusion to the connected model providers. The customer remains responsible for ensuring the content they submit is lawful.
Data retention & training
Hosting summary
Lurus GmbH is established in Germany and states that it is subject to German and EU law. Two processing routes are offered and disclosed per model: a European route, where models are hosted in Europe, and a US or global route, where selected high-performance models are processed in the United States. The vendor states that the region does not alter its privacy guarantees, and that zero data retention and the no-training commitment apply on both. The privacy policy names the infrastructure and model suppliers individually, among them Hetzner Online GmbH, OVH GmbH and IONOS SE in Germany, Amazon Web Services EMEA in Luxembourg, Google Cloud EMEA and Microsoft Ireland in Dublin, Nebius in Amsterdam, Scaleway in Paris, BFL in Freiburg and Requesty as a routing service. The public website itself resolves to OVH infrastructure in France. The hosting infrastructure is described as ISO/IEC 27001 certified and C5 attested, a statement that concerns the host rather than the publisher.
Things to keep in mind
Risks and trade-offs to weigh before adopting Lurus Code.
- Autonomous agents edit files and run commands: review the diffs rather than accepting them wholesale, because the reviewing habit is the first thing to erode
- Prolonged reliance on a planning-and-implementing agent can hollow out a developer's own grasp of the codebase, which matters most when the agent is unavailable or wrong
- The certification badges shown on the home page describe the hosting infrastructure, not the publisher, so do not read them as vendor assurances
- Generated security patches and CWE mappings still need human verification; a passing scan is not proof that a vulnerability is gone
- The US model route sends code outside the EU, so choose the route deliberately if your own obligations require European processing
- You keep the rights to the code you submit but remain responsible for its legality, including anything the agent produces from it
- Converting an account to a Team plan is permanent and cannot be reversed to an individual plan
Setup & Integrations
Technical difficulty
Setup is straightforward for anyone comfortable with a terminal. The command-line client installs globally in a single npm command, followed by one login step, and the site describes reaching a first prompt in under five minutes. Developers who prefer an editor can install the native VS Code extension instead and work from the chat panel. The prerequisites are a working Node package manager and basic command-line familiarity. Deeper configuration is optional rather than required: project rules in a LURUS.md file, event hooks, permission boundaries and Model Context Protocol servers can all be added later as the team's needs grow.
Deployment
Integrations
Supported languages
Behind Lurus Code
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Lurus Code.
Frequently asked questions
What exactly does Lurus Code do?
Is my source code stored or used to train models?
Which programming languages does it support?
How much does it cost and is there a free plan?
How does team billing work?
Where is my data processed?
Can I use it in a CI/CD pipeline?
Is there a mobile app or a public API?
Is Lurus Code itself ISO 27001 certified?
Who is behind the product?
Should you pick Lurus Code?
Lurus Code makes an unusually specific promise for an AI coding tool: not that it writes better code than its rivals, but that it can tell you exactly where your code went and what was done with it. The product is built around that claim. Zero data retention is the default on every route, training on customer code is excluded for Lurus and for the connected providers alike, the model and its processing region are named before a request leaves the machine, and a data processing agreement sits in public view alongside a named list of sub-processors. For a European team that has to justify its toolchain to a compliance function, that is the substance of the offer.
The engineering is not an afterthought. Multi-agent orchestration, security scanning with CWE and SARIF output, test generation, semantic code indexing and a permission system with sandbox boundaries add up to a credible agent rather than a wrapper. The commercial model is genuinely unusual too: team members cost nothing, and an organisation funds a shared balance instead of buying seats.
Two reservations deserve weight. The ISO/IEC 27001 certification and C5 attestation shown on the site belong to the hosting infrastructure, not to Lurus GmbH, and no certificate number is published for the publisher itself. And the company is young and small: the legal entity was registered in 2023 under a different name and only became Lurus GmbH in August 2026, with share capital of EUR 25,500. Some of the site's own metadata has not kept pace, including a dead GitHub link and a founding year the register contradicts. Buyers who need durable guarantees should ask about the publisher's own certification roadmap before committing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.