← Back to Lumen
Security

The model never becomes the authority.

Lumen places identity, permissions, evidence, and consequential action controls outside the interchangeable model brain.

Updated September 29, 2026

Current security model

Authenticated devices

The Mac and iPhone bridge verifies the devices participating in a continuation.

Typed authority

A model suggestion or tool name is not permission. Actions are constrained by explicit authority.

Human approval

Higher-impact work can pause for the owner’s approval rather than treating fluent intent as consent.

Receipts

Consequential actions, failures, and committed answers preserve evidence for later inspection.

Outbound-data enforcement

The first strict egress run completed 11,298 tests with zero unapproved outbound-data violations. That is engineering evidence for the tested candidate, not a claim that no future defect is possible.

Model isolation

The relationship layer survives a model change. Memory, permissions, tool authority, receipts, and safety standards should not be silently replaced because a more capable model becomes available.

Known work ahead

  • User-held keys and a hardened Identity Vault.
  • Formal retention, export, and deletion controls.
  • Independent security assessment before broad consumer deployment.
  • Documented incident response and vulnerability disclosure processes.

Report a concern

Send a concise description to lumen@talklumen.com. Do not include secrets, credentials, or private third-party data in an initial report.