Langdock alternative? Langdock and Myra AI Workspace compared
As of 11 October 2026
Langdock and Myra AI Workspace solve the same problem. A team wants to work with large language models without data flowing to places nobody signed off. The main difference sits one level lower, in the question of who operates the models. Langdock builds on cloud providers such as Microsoft Azure. Myra runs its own models on its own infrastructure in the EU and adds controlled access to external frontier models.
Which one fits depends on how precisely you need to control which model sees which data. Everything this page says about Langdock comes from Langdock's own website, terms of service and documentation, listed under Sources.
Where Langdock does well
According to its Trust Center, Langdock processes data on servers in the EU by default, and data at rest is stored in Germany. Out of the box only EU-hosted models are switched on. Models with global deployment, which may process data outside the EU, have to be enabled by an administrator, and the platform marks them with a globe icon. Nobody has to configure anything to get there. That default is stricter than Myra's, where EU-only routing has to be switched on.
On training, Langdock states that customer data is never used to train AI models. Its terms go further and describe zero data retention arrangements with Azure, OpenAI, Google, AWS and Mistral.
Langdock is also open about its contracts. The list of sub-processors is part of its public data processing agreement, with the location and transfer mechanism for each entry. There is an addendum for professional secrecy holders in Germany and another for firms covered by DORA, the EU's Digital Operational Resilience Act for the financial sector. As certifications, Langdock names ISO 27001:2022 and SOC 2 Type II.
Then there is breadth: many current models, a mature workflow product, Office add-ins and a long list of integrations. Organisations on Microsoft 365 can keep content with certain Purview sensitivity labels away from the AI. For large organisations, Langdock's security page lists a dedicated single-tenant instance from 2,000 users, and deployment in your own cloud or on premises from 5,000 users.
So Langdock is the better pick in several cases. You want EU processing without touching a setting. You live in Microsoft 365 and want Purview labels to stop files before they reach a model. Or you want a broad catalogue of frontier models, or a publicly documented single-tenant or on-premises option for thousands of users. If controls at the level of the whole workspace are enough for you, there is little reason to switch.
Eleven criteria side by side
| Criterion | Langdock (according to Langdock) | Myra AI Workspace |
|---|---|---|
| Application hosting | Microsoft Azure, Frankfurt | Myra infrastructure with a BSI C5 Type 2 attestation |
| Who runs the models | Microsoft Azure, Google Cloud, AWS Bedrock, OpenAI as well as Mistral (terms of service, Annex 1) | Myra models (for example Qwen, Gemma, Mistral Small) on Myra's own EU infrastructure, labelled “Hosted by Myra (Germany)”; on paid self-service plans they need the “EU-Gov” add-on. External models can be added |
| EU processing | EU by default, only EU-hosted models enabled; admins can enable global models | EU-only routing can be enforced per gateway or for the whole organisation; it is off by default |
| Blocking models | Model control at workspace level (documentation: workspace settings) | Per project: the access tier “Local only” allows Myra models alone and blocks cloud models and web search |
| Personal data in chat | In workflows, a Guardrails node detects personal data and stops the run. Masking in chat is not described in Langdock's documentation | Reversible masking before external models, with “Preview”; the original values return in the answer. Available in every plan |
| Control before sending | Purview label block: content from Microsoft 365 integrations with blocked sensitivity labels does not go to the AI | A privacy indicator next to the model picker shows where the data will go before it is sent (see below) |
| Audit log | Admin actions and failed logins with before and after values, kept for 90 days, retrievable by customers via API. Tamper evidence is not described in Langdock's documentation | Admin changes and security events are logged, tamper-evident via a hash chain on request. Customer admins have no audit-log screen; Myra's platform admins read the log via API |
| Training on customer data | Not used for training, according to Langdock; zero data retention with the model providers named in its terms | Myra does not use customer data to train AI models; for external models, the provider's terms apply |
| Professional secrecy (Germany) | Addendum for professional secrecy holders (Trust Center) | Myra offers a confidentiality undertaking under § 203 StGB and § 43e BRAO |
| Certifications | ISO 27001:2022, SOC 2 Type II; Langdock does not list a C5 attestation on its pages | Myra Security: ISO 27001 on the basis of IT-Grundschutz; Myra infrastructure with a BSI C5 Type 2 attestation |
| EU AI Act | Governance add-on with templates and automatic checks of agents | Governance templates map AI Act and GDPR obligations onto the configuration; answers carry the label “AI-generated” |
Prices are left out on purpose. Compare costs once you know which mix of models your teams will actually use.
In Myra, the project decides which model may answer
Every project in Myra has an access tier. The default is “User configurable”, where people choose per chat. “PII protection required” keeps all models available but forces masking on. Set the tier to “Local only” and the model picker shows nothing but Myra models. Cloud models are blocked, as are web search and external tools, and the server refuses cloud requests. Only the project owner can change the setting. So the decision is built into the project and does not depend on each user remembering the rules. One condition: on a paid self-service plan, the Myra-hosted models, and with them any “Local only” project, need the “EU-Gov” add-on.
HR can then work on job applications in one project while marketing uses an external frontier model in the project next door.
What the privacy indicator next to the model picker shows
With every input, a coloured indicator tells the user where the data is going:
- Green, “Local model” or “Local + masking”: the request stays with Myra models.
- Amber, “Privacy on”: an external model answers, and personal data is masked first.
- Red, “Privacy off”: an external model receives the text unchanged.
Amber is where masking does its work. Before an external model sees the request, a detection engine running at Myra replaces personal data with placeholders, from names to IBANs and German tax IDs, which are checked against their checksums. The answer comes back with the original values restored. With “Preview”, users check beforehand what will leave the system, and with “Mask selected text” they cover anything the detection missed. Detection fully supports German and English; if your teams write in other European languages, use the preview to see what gets replaced. A request that only Myra models handle is not masked at all, because the text does not leave Myra. Masking is available in every plan. Under the GDPR it is still pseudonymisation, and the data does not become anonymous.
Who runs the servers under AI Workspace
Myra Security, based in Munich, sells DDoS protection, a web application firewall and a CDN, and has protected critical infrastructure for years. Germany's Federal Office for Information Security (BSI) lists it as a qualified DDoS mitigation service provider. AI Workspace runs on Myra infrastructure that holds a BSI C5 Type 2 attestation. C5 is the BSI's catalogue of security criteria for cloud services. The attestation covers this infrastructure; the application itself is outside its scope.
One practical point for teams outside Germany: the AI Workspace interface is available in German and English only.
Myra runs open-weight models on its own infrastructure in the EU and also offers secure access to frontier models. According to its own terms, Langdock provides its models through cloud providers such as Microsoft Azure, AWS and Google Cloud. Sascha Schumann, CEO Myra Security
Three questions to settle before you choose
The table lists features. We would make the decision on three questions.
Is there data that no external model may see? Think of client confidences, health records or personnel files. If so, find out whether you can enforce that per project in the software, or whether you are relying on training and discipline.
Who will later have to show what happened? The GDPR's accountability principle (Art. 5(2)) requires you to be able to demonstrate compliance, and internal audit and data protection authorities ask exactly this. Ask both vendors to show you which events the log records, who can retrieve it and how long it is kept.
And who owns the infrastructure beneath the models? For some organisations, a hyperscaler's EU data centre is enough. Others want an operator that runs the servers itself.
Further reading: Myra AI Workspace and the German version of this comparison, Langdock oder Myra AI Workspace?
Frequently asked questions
Where does Langdock host its service?
In Frankfurt, according to Langdock's Trust Center, with Microsoft Azure as the infrastructure provider. Data at rest is stored in Germany. Under its terms of service, Langdock provides the models through Microsoft Azure, Google Cloud, AWS Bedrock, OpenAI as well as Mistral (as of 11 October 2026).
Does Langdock process data only in the EU?
By default, yes, says Langdock: in the standard configuration only EU-hosted models are switched on. Administrators can additionally enable models with global deployment that may process data outside the EU. Langdock marks these with a globe icon.
Where do the models run in Myra AI Workspace?
Myra models run on Myra's own EU infrastructure; in the model picker they carry the note “Hosted by Myra (Germany)”. You can also allow external models from other providers and block them per project. On a paid self-service plan, the Myra-hosted models require the “EU-Gov” add-on.
Does either tool make us compliant with the EU AI Act?
Neither tool takes those obligations off your hands. As the deployer, your organisation stays responsible. Langdock offers a governance add-on with templates for the EU AI Act and GDPR and an automatic check whenever an agent changes. Myra's governance templates map AI Act and GDPR obligations onto the configuration, and answers carry the label “AI-generated”.
Can I test both before deciding?
Yes. Langdock describes its trial on its own pricing page. With Myra AI Workspace you start a pilot in your own tenant, with SSO and a data processing agreement. Give both the same three real tasks from your daily work. Demo prompts reveal little.
Sources
- Langdock: Security (langdock.com/de/security, in German), retrieved 11 October 2026
- Langdock Trust Center (certifications, addenda), retrieved 11 October 2026
- Langdock Trust Center: FAQ, retrieved 11 October 2026
- Langdock: Terms of Service, Annex 1 (model provision, zero data retention), retrieved 11 October 2026
- Langdock: Data Processing Agreement v2.1, Annex 2 (sub-processors, in German), retrieved 11 October 2026
- Langdock documentation: workspace settings (models), retrieved 11 October 2026
- Langdock documentation: Audit Logs API, retrieved 11 October 2026
- Langdock documentation: Guardrails node in workflows, retrieved 11 October 2026
- Langdock documentation: Sensitivity Label Policy, retrieved 11 October 2026
- Langdock: pricing and governance add-on (in German), retrieved 11 October 2026
- Regulation (EU) 2016/679 (GDPR), EUR-Lex, retrieved 11 October 2026
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex, retrieved 11 October 2026