Skip to main content

What is Lumen?

Lumen is an AIDR, an AI Detection & Response service. It gives an organization visibility into, and control over, how its people and its applications use generative AI.

A family of collectors, the sensor, captures AI interactions across browsers, internal applications, agentic and MCP traffic, API gateways, and cloud AI platforms. Each interaction is inspected in real time for LLM-specific risks, and Lumen can Log, Redact, or Block it per policy. Telemetry and findings live in a multi-tenant console.

The Lumen console: AI activity, findings, and what Lumen did about each interaction

Two deployment postures​

  • Workforce monitoring. The organization owns the endpoints through Intune, Jamf or Workspace ONE, and deploys the endpoint agent with its capturing proxy and Claude Code hook guard, plus the browser extension, to managed machines. This is where the locally installed sensor lives, and it is the emphasis of the product.
  • AI application development. The organization builds AI systems and instruments them inline. The MCP proxy for agentic traffic and the LiteLLM gateway plugin are available today, both running against a co-located agent; an Application SDK, the Kong and Portkey plugins, cloud ingestion and OpenTelemetry are on the roadmap. See the collector coverage matrix for what ships today.

One tenant can run any mix of collectors. Every collector is registered in the console, associated with a policy, and given a tenant-scoped identity at enrollment.

What it detects​

Six detection classes, mirroring the risks specific to LLM traffic:

ClassExamples
Prompt injection & jailbreakinstruction override, system-prompt exfiltration, base64 or homoglyph obfuscation
Sensitive-data exposurecredentials and secrets, PII, financial data, org-confidential identifiers
Malicious entitiesphishing URLs, C2 domains, known-bad IPs in prompts or responses
Toxic or harmful contentviolent, abusive, hateful, or self-harm content
Languageallowlist or denylist by detected language
Topic violationsconfigurable category restrictions such as legal advice and medical advice

Details in Detection classes.

How it responds​

Every interaction resolves to one effective action:

  • Log. Pass through and record.
  • Redact. Replace the matched spans before the model sees them in a prompt, or the user sees them in a response. The interaction proceeds.
  • Block. Stop the request or response and return a policy message.

The verdict is computed locally, inline, in single-digit milliseconds. The cloud never sits in the request path. See the policy model.