THE TRUST CENTRE

Ask the hard questions.
We answer plainly.

Before you trust anyone with your business, ask what a sceptical board would ask. Here are those questions, by the role that asks them, with honest answers: what is available today, what is still in development, what we agree with you in writing and what we do not claim at all.

Read the questions

Four honest answers

  • Available todayWorks in a product, or in how we deliver, now. We can show it to you.
  • In developmentBeing built. We say how far it has come and never sell it as finished.
  • Agreed with youSettled in writing, in your agreement or operating plan, rather than assumed.
  • Not something we claimA claim we do not make. The answer says what we offer instead.

THE BOARD PACK

Nine readers.
One honest pack.

Every executive reads the same proposal for a different reason. Open a section to see the questions that reader will ask. Each question starts open, and shows its honest status once you have read the answer.

  • Open: not read yet
  • Available today
  • In development
  • Agreed with you
  • Not something we claim
Niello · Board packFor discussion

The hard questions

Asked as a sceptical board would ask them. Answered plainly.

CEO
CFO
COO
AI lead
CISO
CIO
Counsel
People
Procurement
Answered so far0 of 27

An illustration of a board pack. The questions and answers are the ones on this page.

THE HARD QUESTIONS

Asked the way they are
asked in the room.

Every concern here is written the way a sceptical executive would say it. Choose a role to see what that reader will ask. Each answer says plainly whether it is available today, in development, agreed with you in writing or not something we claim.

Showing every question, for every role.

Data and security

Data leaving the companyAsked by
  • CISO
  • CIO
  • Counsel

The moment our data leaves our environment, this conversation is over.

Then it can stay inside. Lumen works on your people’s own devices. Lumen Intelligence is customer-hosted, on a Linux virtual machine, on Kubernetes or fully air-gapped; personal data stays in the appliance, and any outbound link is mutually authenticated and yours to switch off. Bridge can run a model on infrastructure you control. Where a model outside your boundary is part of the design, the privacy gateway removes or pseudonymises sensitive values first and fails closed. The boundary for your scope is drawn in discovery and written down before anything is connected.

Status
Available today
What you can ask us for
A data-flow walkthrough of your scope: every system, every model call and where each one runs.
Security and governance
Training on your dataAsked by
  • CISO
  • Counsel
  • Procurement

Will our data end up training somebody else’s model?

Not by assumption. Which model providers are used, and on which terms, is chosen with you and listed in writing. Bridge routes each request to a provider and model suited to the task, including one you host yourself, so work that cannot tolerate a third party does not have to use one. Whether your data may be used to improve anything, by us or by a provider, is a term in your agreement, stated plainly, not a default buried in a policy.

Status
Agreed with you
What you can ask us for
The data-use terms in writing, and the model providers in your scope with their own terms.
Security and certificationsAsked by
  • CISO
  • Procurement

Show me your certifications, or we stop here.

We do not claim any security certification or third-party attestation on this site, and we will not imply one. If your process requires a specific attestation, ask us and you will get a direct answer about what exists today. What we can show you now is the design: agents and identities mapped to owners in Mesh, sensitive actions routed for review, a hash-chained audit log in Lumen Intelligence, and customer-hosted or air-gapped options where the risk calls for them.

Status
Not something we claim
What you can ask us for
Written answers to your security questionnaire, and an architecture review with your security team.
Security and governance
Agents with accessAsked by
  • CISO

An agent with access is a new identity I don’t control.

Then control it like one. Mesh maps each agent, model, tool and non-human identity to an owner, shows the access a workflow needs before it is granted, and applies policy to model requests and tool actions, explaining why an action was allowed or denied. For developers, Dex runs coding agents behind a policy gate that fails closed, and an agent cannot edit its own gate.

Status
Available today
What you can ask us for
A walkthrough of identity and permission mapping on a workflow from your scope.
Mesh
Manipulated contentAsked by
  • CISO
  • CIO

Can someone take over an agent by hiding instructions in an email or a document?

No product makes that risk disappear, and we do not claim one does. The design limits what content can do on its own: Lumen Mail treats incoming mail as untrusted and holds replies to automated mail (it is in pilot); Mesh routes sensitive operations to a person; and policy applies to the actions an agent takes, not only to the text it reads.

Status
Not something we claim
What you can ask us for
A review of every action an agent could take in your scope, and which of them need a person.
Third partiesAsked by
  • Procurement
  • CISO
  • Counsel

Which third parties touch our data, and where?

That depends on the scope, so it is listed for your scope rather than for everyone: each model provider, hosting location and service that would handle your data, with customer-hosted and air-gapped options where no third party is acceptable. The list is part of the agreement, and a change to it is raised with you.

Status
Agreed with you
What you can ask us for
A written list of every third party in scope, where it runs and what it receives.
Tools already in useAsked by
  • CIO
  • CISO

Our developers already use coding agents. I can’t see what they do.

Dex gives developers one place to run the coding agents they already use, on macOS and Linux, behind a deterministic gate that runs before tools execute and fails closed. A session that is not governed is shown as not governed, never as safe, and each pull request carries a receipt of what changed.

Status
Available today
What you can ask us for
A working session with your developers on Dex and its doctor check.
Dex

Risk, law and accountability

Model risk and accuracyAsked by
  • CEO
  • Counsel
  • CIO
  • AI lead

These models make things up. Why would I let one near a customer?

They do make mistakes, and nobody can honestly promise otherwise. The work is designed around it. Builder evaluates a workflow on representative examples, failure modes included, before release; Bridge compares evaluation results before promoting a version and keeps a path back to the previous one; Mesh routes sensitive actions to a person; Lumen shows the sources behind a result. Consequential decisions stay with a named person.

Status
Available today
What you can ask us for
An evaluation on your own examples during the pilot, showing where it fails as well as where it works.
The accountability register
AccountabilityAsked by
  • CEO
  • Counsel
  • AI lead

When an agent gets it wrong, who answers for it?

A person. Every agent works alongside someone who answers for it. Mesh maps agents, models and tools to their owners and connects each decision to its inputs, policies and approvals, so the answer to “who approved this?” is a record rather than a meeting.

Status
Available today
What you can ask us for
An accountability register for your scope: each decision, its owner and the evidence it leaves.
The accountability register
Regulatory exposureAsked by
  • Counsel
  • CISO

Are we about to walk into the EU AI Act and GDPR blind?

Not if the roles are worked out before the build. The EU AI Act sets duties by role, such as provider and deployer, and by risk: some practices are prohibited, high-risk systems carry mandatory requirements, human oversight among them, and some systems carry transparency obligations. GDPR sets duties by role too, such as controller and processor. Which of them apply depends on the use case and on who you are in it, so we work through it in discovery, use case by use case. We do not give legal conclusions; your counsel does.

Status
Agreed with you
What you can ask us for
A written description of each use case, its data, its users and its human oversight, prepared for your counsel’s assessment.
The accountability register
Ownership of outputs and IPAsked by
  • Counsel
  • Procurement

Who owns what gets built, and what the models write?

Ownership of your data, of the outputs produced for you and of the workflows, instructions and evaluation sets built with you is written into the agreement before work starts, not left to interpretation. Model providers’ own terms also apply to what their models produce, so we show you which providers are in scope and what their terms say.

Status
Agreed with you
What you can ask us for
An ownership schedule listing each thing built for you and who owns it.
What you own
Evidence for auditorsAsked by
  • Counsel
  • CISO

When the auditors ask how a decision was made, what do we hand them?

A record rather than a reconstruction. Mesh connects decisions to their inputs, policies and approvals and keeps a traceable record for security and risk teams to review; Lumen Intelligence keeps a hash-chained audit log of changes; Dex attaches a receipt to each pull request. What is recorded, and for how long, is agreed with you.

Status
Available today
What you can ask us for
A sample evidence record from a workflow in your scope.

Money and proof

Cost overrun and proving valueAsked by
  • CFO
  • CEO
  • COO

AI projects overrun, and then nobody can tell me what we got for the money.

Agree the measure before the money. Discovery ends with a definition of success and a named owner; the pilot is reviewed against those criteria, and each stage ends with a decision to continue, change or stop. A change in scope is quoted as a change rather than absorbed quietly. The value scenario lets you test the case with your own inputs, including a case that never pays back.

Status
Agreed with you
What you can ask us for
Success criteria, a baseline measure and a stop point for every stage, in writing.
The value scenario
Running costsAsked by
  • CFO
  • CIO
  • COO

The pilot is cheap. What does it cost when everyone uses it?

Running costs grow with use, mostly through model usage, so they belong in the business case from the start, not after rollout. Bridge routes each request to a provider and model suited to the task, so the cost of usage is a choice you can revisit. Commercial terms are agreed after discovery, when the scope is known; we do not publish prices that would not describe your case.

Status
Agreed with you
What you can ask us for
A running-cost estimate for your scope, at pilot and at full use, with every assumption shown.
Engagement options
Pilots that never shipAsked by
  • CEO
  • COO
  • AI lead

We’ve done pilots before. They never leave the pilot.

A pilot should end in a decision, not drift. We start from one meaningful problem with a named owner and a definition of success, prove it on representative examples with the people doing the work, and plan the rollout, the owners and the handoff before anyone calls the pilot a success.

Status
Available today
What you can ask us for
A pilot scope with success criteria and the decision it will inform.
Our approach
Proof from othersAsked by
  • Procurement
  • CEO
  • AI lead

Who else uses this? Show me the logos.

We publish no customer names, logos or results on this site, and nothing here is presented as one. Better evidence is your own problem worked through with your own examples. Everything we describe is either shown working, labelled as in development, or written into your agreement.

Status
Not something we claim
What you can ask us for
A working session on one of your own problems, with your own examples.

People

Understanding how work happensAsked by
  • People
  • CEO
  • COO
  • AI lead

You say you capture how work really happens. Does that exist yet, or is it a slide?

Part of it exists. Lumen Intelligence builds an evidence-backed picture of people, groups, reporting lines and accounts from your directories today, inside your environment. Learning from everyday activity, the part that shows how work actually moves, is still in development, and any activity feed you see from us is an illustration. Until it is built, the picture of how work moves is put together with your people, with their consent.

Status
In development
What you can ask us for
A demonstration of the organisation graph on your own directory, and a plain account of what is still being built.
Lumen Intelligence
Change management and adoptionAsked by
  • People
  • CEO
  • COO
  • AI lead

We bought tools before. Nobody used them.

Adoption is the hard part; working inside organisations as a consultancy is how we learned it. The people doing the work help shape the workflow and have a voice in the pilot review. Rollout comes with owners, review points and support for the teams it changes, introduced deliberately rather than switched on for everyone at once.

Status
Available today
What you can ask us for
A rollout plan naming who changes what, when, and who supports them.
Our approach
Jobs and rolesAsked by
  • People
  • CEO

Be straight with me: is this about cutting jobs?

Work changes, and we will not pretend it does not. What we design for is people keeping the judgment and the accountability while agents take on the busywork. Decisions about roles are yours, and the replica shows where time really goes, so those decisions rest on evidence rather than a vendor’s estimate. We do not promise headcount savings.

Status
Not something we claim
What you can ask us for
An honest view of how each role in scope would change, before the pilot starts.
Skills and oversightAsked by
  • People
  • CIO
  • COO

Who teaches my people to work with this, and to overrule it?

Preparing the team is part of rollout, not an afterthought. The people who will use the workflow, and the people who oversee its agents, are introduced to it deliberately: what it does, where it can be wrong, when to step in and how. Agent input pauses when a person takes over in Lumen Spaces, and sensitive actions wait for a person in Mesh.

Status
Agreed with you
What you can ask us for
A plan for preparing each team in scope, including the people who oversee the agents.

Running it, and leaving

Integration with existing systemsAsked by
  • CIO
  • COO
  • AI lead

It has to work with what we already run, not beside it.

Some connections exist today: Lumen Intelligence reads your directory services, Signals connects analytics and operational feeds, and Builder composes models, tools and approvals into a workflow. Everything else in your scope is named in the Connect stage and confirmed in writing before the pilot is agreed, including anything that would need to be built.

Status
Agreed with you
What you can ask us for
An integration map for your scope, marking what exists, what needs building and who owns each connection.
Our approach
Incident responseAsked by
  • CISO
  • CIO
  • COO

When something goes wrong at night, who picks up, and what can they see?

Who is called, how quickly and who tells whom is agreed with you and written into the operating plan; we do not publish response times that would not describe your case. What the people responding have to work with: a record linking each decision to its inputs, policies and approvals in Mesh, a hash-chained audit log in Lumen Intelligence, a path back to a previous release in Bridge, and a policy gate that fails closed in Dex.

Status
Agreed with you
What you can ask us for
An incident runbook for your scope: roles, contacts, rollback and notification.
Security and governance
Agents that send mail and share filesAsked by
  • CIO
  • Counsel

If agents send mail and share files in our name, what stops a mistake reaching a customer?

Lumen Mail gives an agent its own mailbox on a subdomain you own. Records are created, never changed or deleted; anything that would affect your existing mail stops for a person to decide; repeated sends never deliver twice, and replies to automated mail are held. It is in pilot. Lumen Docs, with versions and share links that expire, carry a password and limit downloads, is in development: none of it is available yet.

Status
In development
What you can ask us for
The current state of the pilot, and which parts of your scope would depend on something still in development.
Lumen Mail
SupportAsked by
  • CIO
  • Procurement
  • COO

After go-live, do we get a team or a ticket queue?

The deployment, ownership and support model is agreed before rollout, so you know who answers, through which channel and for what. We do not publish support tiers or response times here, because they are set around your deployment.

Status
Agreed with you
What you can ask us for
A support model in writing: who, how, when, and what is out of scope.
Lock-in and how to leaveAsked by
  • CIO
  • CFO
  • Procurement
  • AI lead

Every platform says it’s open. How hard is it to leave you?

It should be easy to leave, and you should be able to check that before you sign. The exit is planned at the start: what you own, what is exported and in which form, how your team takes over and how our access ends. Bridge keeps the choice of model open, so instructions and evaluations are not tied to one provider, and customer-hosted deployments already run on your infrastructure. What is exported, when and how, is agreed with you.

Status
Agreed with you
What you can ask us for
An exit plan in the statement of work, and a rehearsal of it before you depend on the system.
Exit and handback
Company continuityAsked by
  • CEO
  • CFO
  • Procurement
  • CIO

You’re not a household name. What happens to us if you disappear?

You should not have to take our future on trust, so design for the case where we are not there. Your data can be exported; customer-hosted deployments already run on your infrastructure; and handback means your own team runs the system, with documentation, runbooks and configurations, before the engagement ends, so no single person at Niello holds knowledge you cannot get. We do not publish figures about the company here; ask us directly in procurement.

Status
Agreed with you
What you can ask us for
A handback plan and an export test in the statement of work, and a direct conversation about the company.
The company story

WHAT YOU CAN ASK US FOR

Ask for the evidence.
In writing.

Every answer ends with something you can ask us for. Choose what your review needs and the page prepares a draft for you to send from your own email. Nothing is sent from this page.

Requests
Data and security
Risk, law and accountability
Money and proof
People
Running it, and leaving
Your draft
Hello Niello,

For our review, please prepare the following:

- (Choose what your review needs on the page.)

Our organisation:
The role reviewing this:

Opens your own email app with the draft to review and send. Prefer to talk first? Start a conversation.

WHAT YOU WILL NOT FIND HERE

The claims we leave out.
On purpose.

A trust page is easy to fill with badges and borrowed confidence. We would rather you notice what is missing, and ask us about it. We also sell the products named in these answers; read them with that in mind and ask for the evidence behind each one.

  • No customer names, logos or resultsEvidence is your own problem, worked through with your own examples.
  • No savings percentagesThe value scenario runs on your inputs, and says so when a case never pays back.
  • No attestations we cannot show youIf your process needs one, ask, and you will hear plainly what exists.
  • No published response timesSupport and incident terms are set around your deployment, in writing.
  • No model that never errsMistakes are designed for: evaluation, review, evidence and a way back.
  • No legal conclusionsWe work through roles and obligations with you; your counsel decides.