Niello/Security & privacy
Security & privacy

Your screen never
leaves your screen.

Lumen can record what you did today and play it back like a timelapse. That recording is written to your own disk and read from your own disk. There is no upload step, because there is nowhere for it to go.

The timelapse

Scrub back through your own day

Lumen keeps a picture of what was on screen as you worked. Not to watch you — so that you can go back and find the thing you had open when you made the decision, and so the day’s write-up is drawn from what actually happened.

09:14Intake portal opened
09:31Northwind contract, clause 9
10:02Pricing sheet, third revision
11:00Board prep — call
14:22Reply drafted to legal
16:48Diff reviewed, shipped
09:00your day, on your disk18:00

Where it is kept

On the machine that recorded it, in your own storage, alongside the rest of your workspace.

  • Written to local disk as it is captured
  • Read back locally when you scrub the day
  • Deleted when you delete it — no copy elsewhere to chase
  • Processed on your machine, not shipped out to be understood

Where it is not

The parts of this that usually make a security team say no, and why they do not apply.

  • Not uploaded to us for processing
  • Not held in a shared bucket with other companies’ footage
  • Not used to train anything
  • Not visible to Niello — we cannot open what we never receive
Nothing joins, nothing shows

No bot in the invite.
Nothing on the shared screen.

Lumen attaches to the window you point it at rather than dialling into the call. There is no extra participant on the guest list, and the assistant is not sitting in the middle of the screen you are about to share.

  • Attach to an application. Point it at a single window — your call, your document, your terminal — and it works from that.
  • You pick what it hears. Your microphone, the call’s audio, or nothing at all. It is a choice you make each time, not a default you discover later.
  • Wake word stays local. Listening for it runs on the device; nothing is sent while it waits.
A word on the obvious question: recording other people is governed by law, and that law differs by country and by state. Lumen makes capture an explicit choice so you can meet whatever your obligations are — it does not make that decision for you, and we would be wary of any tool that claimed to.
LumenStart a recording
What should it capture?

A single app window

Point it at one window and nothing else
Chosen

Just your microphone

Only what you say
Available

You and the room

Microphone plus the call’s audio
Available
Controls you can enforce

Set once, applied for everyone

These are not preferences each person finds in a settings screen. They are rules the workspace applies before anything runs.

Residency

Which models may be used

Require that a class of material is only ever handled by a model running on your own hardware. Anything else is simply not offered.

Capture

What may be recorded

Turn screen capture off entirely, restrict it to chosen applications, or leave it to the individual. Your call, not theirs.

Retention

How long it is kept

Set how long the record and the screen history live before they are removed, and have that happen without anyone remembering to.

Reach

What an assistant can read

An assistant reads only the collection you hand it. There is no ambient access to the rest of the disk.

Connectors

Which tools may be joined

Approve the calendar and the drive, refuse the rest. A connector cannot widen what an assistant may see.

Evidence

What gets written down

Every decision the boundary makes is recorded, so the answer to “what was allowed, and when” is a query rather than an investigation.

Self-hosted

Run the whole thing
inside your own walls.

For organisations that cannot use a supplier’s infrastructure at all, Niello can be deployed into your own environment — your servers, your network, your rules. Nothing about the product depends on reaching us.

  • Your infrastructure. Deployed into the environment you already run and already audit.
  • Your models. Point it at the hardware you have, and keep inference inside the same walls.
  • Your identity provider. Single sign-on against the directory you already use.
  • No dependency on us. It keeps working whether or not it can reach anything of ours.
Talk to us about self-hosting
DeploymentYour environment
Workspace
your servers
Models
your hardware
Screen history and record
your storage
Anything reaching Niello
nothing required
Where we are today

What we will not claim

Mapped is not certified. The record lines up with EU AI Act record-keeping, ISO 42001, SOC 2 and NIST AI RMF so it fits the frameworks you already report against. Niello has not been audited against any of them and does not hold those certifications. When that changes we will say so with the certificate attached, and not before.

Local-only is a mode, not a default. Out of the box, the workspace can reach a hosted model. Local-only mode is the setting that keeps everything on your machine — it is available on every tier including the free one, and it can be enforced centrally rather than left to each person.

Connectors are in preview. The eleven integrations are built but not yet joined to live accounts. Everything else works today without them.

Ask us the hard question first.

Most security reviews start with “where does the data go?”. We would rather answer that on the first call than the fifth.