
Louhe
Finnish AI platform that reads the events already produced by access control, alarm and locking systems, learns each site's normal behaviour, flags anomalies and insider risks in real time, and audits how premises are genuinely used.
What is Louhe?
Louhe is a physical security analytics platform from the Finnish company Louhe Oy. Rather than asking organisations to buy new sensors, it connects to the infrastructure already installed — access control, alarm systems, fire detection, electromechanical locking and video surveillance metadata — and applies machine learning to the events those systems generate every day.
The brand covers two products. LOUHE Detection & Response works in real time: it learns what normal movement looks like inside each security perimeter, then detects and classifies deviations so that operators work from a short, ranked list of tickets instead of a wall of screens. LOUHE Insights works on historical data, turning access logs, system data, process information and guard reports into a picture of how a site is actually used: perimeter integrity, people flows, credential misuse, tailgating, critical doors, occupancy and underused space.
Both rest on explainable AI. The company states plainly that there are no black-box algorithms and presents findings with human-readable descriptions aimed at control room operators. Privacy is built into the design: customers strip personal identifiers before transfer, Louhe works on identifiers only and declares itself technically unable to re-identify individuals. Video feeds are never processed, only metadata such as counts of people passing a gate. An EU AI Act declaration argues that the service sits outside the regulation's high-risk categories because it is preparatory and keeps a human in the loop.
Louhe carries out the integration itself, through log files, the source system's own API, a lightweight application running near that system, or a database copy; about two weeks should be set aside for a full deployment. No prices are published: the route in is a demonstration, then a free proof of concept on the customer's own data, then a contract signed directly or through a reseller. Named customers include the Finnish Broadcasting Company, Kela and the airport operator Finavia, and resellers cover Finland, Sweden and Estonia. The company reports ISO 27001 certification of its information security management system and LenelS2 factory certification for its OnGuard interface.
What it does
- Analyse access control events in real time and classify anomalies automatically
- Learn each security perimeter's normal behaviour and flag departures from it
- Correlate alarm, access control, fire detection, locking and video metadata into one picture
- Detect insider threats, credential misuse and tailgating
- Produce audit-ready reports and a threat report for compliance and stakeholders
- Map how premises are really used, from people flows to occupancy and underused space
- Build a digital twin of floor plans and highlight critical doors and zones
When to use Louhe / When not to
A quick filter to help you decide if Louhe is the right fit.
When to use Louhe
- Physical security managers who want more from the access control and alarm systems they already own
- SOC and control room operators drowning in alerts and looking for a short, explained list of anomalies
- Security and compliance teams in critical infrastructure who must produce audit-ready evidence
- Facility and property managers measuring occupancy, people flows and underused space
- Airports, hospitals, data centres, banks and government sites exposed to insider threats
When not to use Louhe
- Buyers who need a published price list or a self-service sign-up, since everything runs through a sales conversation
- Developers looking for a public API or developer documentation, as none is published
- Teams wanting a mobile application: no iOS or Android app exists
- Organisations expecting video analytics, since Louhe reads surveillance metadata and never the footage itself
- Sites with no electronic access control, alarm or locking system to connect to in the first place
How to use Louhe
A typical end-to-end flow, from setup to results.
- Ask for a demonstration through the contact form on the Louhe website
- Sit through the demonstration and agree on which of your security systems would feed the tool
- Run a proof of concept on your own data, free of charge, to measure what the analysis actually returns
- Decide with Louhe how the data will reach it: log files, the source system's API, a lightweight local application or a database copy
- Strip personal identifiers on your side so that only identifiers are transferred
- Give Louhe the details of the systems in use and their access credentials; Louhe does the technical integration work
- Allow roughly two weeks for the full deployment of the Detection and Response service
- Have security staff trained by Louhe on the operator, inspector and insights views
- Work day to day from the operator view, using focus mode for tickets and the inspector view to search events and read the threat report
- Take Insights reports monthly or quarterly, or run the offline mode from a CSV file when the environment forbids any network connection
Pros & Cons
Pros
- Works on the security systems you already own instead of requiring new hardware
- Explainable AI is a stated design choice, with detections written in plain language for operators
- Serious privacy posture: pseudonymisation, no video footage processing, declared inability to re-identify
- A published EU AI Act declaration, which very few security vendors bother to write
- ISO 27001 certification of the information security management system and LenelS2 factory certification
- A free proof of concept on your own data before any commitment, with Louhe doing the integration work
- European vendor, Finnish entity, Finnish governing law and named public-sector references
Cons
- No public pricing at all: no pricing page, no figures anywhere on the site
- No public API and no developer documentation
- No mobile application on either store
- The only published contract is an evaluation licence; no commercial terms are available to read
- No data processing agreement, no subprocessor list and no retention period in figures
- No hosting country or region is declared anywhere
- The footer privacy policy covers only the website form, and it still carries an out-of-date postal address
Pricing & Plans
No price is published anywhere on the Louhe website. There is no pricing page, and the full sitemap contains no plan, tier or figure; the product is sold under contract, either directly or through the reseller network in Finland, Sweden and Estonia. Free access does exist, but it is deliberately bounded: the published evaluation licence for Louhe Insights is granted free of charge, is revocable at any time, and is limited to short-term internal evaluation and testing, with commercial use excluded. A proof of concept on the customer's own data is also offered at no cost before any commitment. The only monetary figure on the site is a one hundred euro liability cap in that evaluation licence, which is not a price.
Data, GDPR & hosting
A consolidated view of how Louhe handles your data.
GDPR overview
GDPR is addressed concretely, but across two documents with different scopes. The privacy policy linked in the footer covers only the website contact form register; a separate, unlinked Louhe Insights data protection statement covers the product itself. Both name Tero Takalo as controller and Hannes Huotari as register contact, list the categories of data held, and set out rights of access, rectification, erasure, objection, restriction and portability, exercised by email to support@louhe.com. The Finnish data protection ombudsman is named as supervisory authority. Transfers outside the EU and EEA are governed by a general lawfulness clause. The company also publishes an EU AI Act declaration and states that personal data reaches it only in pseudonymised form. No data processing agreement, no subprocessor list and no retention period in figures are published.
Who owns the data?
The published evaluation licence draws a clear line. The licensee keeps ownership of the data sets it analyses with Louhe Insights, and the underlying access control records stay in the customer's own systems. Louhe and its licensors retain every intellectual property right in the software itself and, notably, in the reports it generates. Any feedback a licensee offers is assigned to Louhe outright, with no compensation. Personal identifiers are stripped by the customer before transfer, so Louhe works on identifiers alone and states that it is technically unable to re-identify anyone. Louhe uses subcontractors for parts of the service but never names them, and no data processing agreement is published.
Reuse rights
Reuse rights are narrow. The evaluation licence is free of charge but revocable, non-exclusive, non-transferable and limited to internal evaluation and testing within the licensee's own entity; commercial use is excluded. Reports produced with the tool may be shared inside the licensee's organisation, but passwords and access may not be shared outside it. Reverse engineering, disassembly, decompilation, translation, modification and adaptation are all forbidden, as is any attempt to learn the source code or the underlying algorithms. When the evaluation period ends, the licensee must stop using the tool and delete every file supplied by Louhe; Louhe may also disable or destroy the software remotely. Separately, the product data protection statement reserves the right for Louhe to use register information to perform, develop and market its own products and services. Finnish law governs, and disputes go to arbitration in Helsinki.
Data retention & training
Hosting summary
Louhe declares no hosting country and no hosting region anywhere on its site. The only geographical statement is a transfer clause: personal data is transferred outside the EU and EEA solely in accordance with applicable data protection law. That is a lawfulness clause, not a declaration of where the platform runs. What is described is the security regime rather than the location. Data is stored electronically in a Louhe service database to which only administrators have access, protected by role-based access rights, with interface views restricted to what each role needs. Encryption and access controls are claimed to protect data in transit and in processing. Subcontractors process parts of the service under agreements with Louhe, but none is named and no subprocessor list is published. For the most sensitive environments, Louhe Insights can be run entirely offline from a CSV file on a disconnected machine, leaving nothing on the local disk. The governing law is Finnish and disputes go to arbitration in Helsinki.
Things to keep in mind
Risks and trade-offs to weigh before adopting Louhe.
- The tool watches how people move through buildings; even pseudonymised, that data can be re-identified by the customer, so internal governance matters more than the vendor's guarantees
- Anomaly scores describe behaviour, not intent, and treating a flagged employee as a suspect is a management decision the software cannot make for you
- Louhe keeps the intellectual property of the reports it generates, and any feedback you give is assigned to it outright
- The published contract is an evaluation licence with a one hundred euro liability cap and an as-is warranty disclaimer; the commercial terms are not public
- The footer privacy policy covers only the website form and still shows an out-of-date Helsinki address; the document that covers the product is not linked from any page
- The ISO 27001 announcement names the certification body but no certificate number, so the claim cannot be verified from the site alone
- The domain louhe.com was registered in 2007 and was still for sale in 2013, long before the company existed; old archived pages of that domain have nothing to do with this vendor
Setup & Integrations
Technical difficulty
Low for the customer, because Louhe does the work. The company says it takes full responsibility for implementation, from system setup to configuration, and that no integration has ever failed for technical reasons. The customer supplies details of the systems in use and their access, and pseudonymises data before transfer. The technical work takes a few days, mostly on Louhe's side, and about two weeks should be set aside for full deployment of Detection and Response. Four connection routes exist, from log file transfer to real-time integration through the source system's API. Training and support are included.
Deployment
Integrations
Behind Louhe
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What is Louhe?
What data does it work on?
Does Louhe watch video footage?
How is personal data protected?
Is there an API?
How much does it cost?
Is there a free trial?
How long does deployment take?
What certifications does the company hold?
Who is behind Louhe?
Should you pick Louhe?
Louhe is a focused, unusually candid product. It does one thing: it reads the events that access control, alarm, locking and surveillance systems already generate, learns what normal looks like on each site, and surfaces what departs from it. The pitch is not more hardware but more value from the hardware already bought, and the two products make that concrete — Detection and Response for the control room, Insights for the audit and the floor plan.
What sets it apart is the seriousness of its privacy and transparency work. Pseudonymisation is imposed at the customer's end, video footage is deliberately left untouched, explainability is a stated design constraint rather than a slogan, and the company has taken the trouble to publish an EU AI Act declaration and to have its information security management system certified to ISO 27001 by a FINAS-accredited body. For airports, hospitals, data centres and government sites, that combination matters more than a feature list.
The reservations are all about what is not published. There is no price of any kind, no commercial contract to read, no data processing agreement, no subprocessor list, no retention period in figures and no hosting country. The only legal document available is an evaluation licence with a one hundred euro liability cap. The footer privacy policy covers the website form alone and still carries an old address. None of this makes the product weak, but it does mean that anyone evaluating Louhe will get the answers in a sales meeting rather than from the website. Ask for the certificate number, the hosting jurisdiction and the data processing agreement early.
- Choosing a selection results in a full page refresh.
- Opens in a new window.