Your screen never
leaves your screen.
Lumen can record what you did today and play it back like a timelapse. That recording is written to your own disk and read from your own disk. There is no upload step, because there is nowhere for it to go.
Scrub back through your own day
Lumen keeps a picture of what was on screen as you worked. Not to watch you — so that you can go back and find the thing you had open when you made the decision, and so the day’s write-up is drawn from what actually happened.
Where it is kept
On the machine that recorded it, in your own storage, alongside the rest of your workspace.
- ✓Written to local disk as it is captured
- ✓Read back locally when you scrub the day
- ✓Deleted when you delete it — no copy elsewhere to chase
- ✓Processed on your machine, not shipped out to be understood
Where it is not
The parts of this that usually make a security team say no, and why they do not apply.
- ✕Not uploaded to us for processing
- ✕Not held in a shared bucket with other companies’ footage
- ✕Not used to train anything
- ✕Not visible to Niello — we cannot open what we never receive
No bot in the invite.
Nothing on the shared screen.
Lumen attaches to the window you point it at rather than dialling into the call. There is no extra participant on the guest list, and the assistant is not sitting in the middle of the screen you are about to share.
- ✓Attach to an application. Point it at a single window — your call, your document, your terminal — and it works from that.
- ✓You pick what it hears. Your microphone, the call’s audio, or nothing at all. It is a choice you make each time, not a default you discover later.
- ✓Wake word stays local. Listening for it runs on the device; nothing is sent while it waits.
A single app window
Just your microphone
You and the room
Set once, applied for everyone
These are not preferences each person finds in a settings screen. They are rules the workspace applies before anything runs.
Which models may be used
Require that a class of material is only ever handled by a model running on your own hardware. Anything else is simply not offered.
What may be recorded
Turn screen capture off entirely, restrict it to chosen applications, or leave it to the individual. Your call, not theirs.
How long it is kept
Set how long the record and the screen history live before they are removed, and have that happen without anyone remembering to.
What an assistant can read
An assistant reads only the collection you hand it. There is no ambient access to the rest of the disk.
Which tools may be joined
Approve the calendar and the drive, refuse the rest. A connector cannot widen what an assistant may see.
What gets written down
Every decision the boundary makes is recorded, so the answer to “what was allowed, and when” is a query rather than an investigation.
Run the whole thing
inside your own walls.
For organisations that cannot use a supplier’s infrastructure at all, Niello can be deployed into your own environment — your servers, your network, your rules. Nothing about the product depends on reaching us.
- ✓Your infrastructure. Deployed into the environment you already run and already audit.
- ✓Your models. Point it at the hardware you have, and keep inference inside the same walls.
- ✓Your identity provider. Single sign-on against the directory you already use.
- ✓No dependency on us. It keeps working whether or not it can reach anything of ours.
What we will not claim
Local-only is a mode, not a default. Out of the box, the workspace can reach a hosted model. Local-only mode is the setting that keeps everything on your machine — it is available on every tier including the free one, and it can be enforced centrally rather than left to each person.
Connectors are in preview. The eleven integrations are built but not yet joined to live accounts. Everything else works today without them.
Ask us the hard question first.
Most security reviews start with “where does the data go?”. We would rather answer that on the first call than the fifth.