Features
Everything Lamplighter does, and where it does it.
Find every AI tool in use, check what goes into each one on the device itself, and act on it: in the browser, in desktop AI apps and in coding agents. Every item below says whether it is available now or coming.
Where it acts
| Route | BrowserChrome and Edge | Desktop AI appsWindows 11 | Coding agents and CLIsThrough the local AI gateway |
|---|---|---|---|
| A prompt being sent | AvailableChecked when sent, never while typing | ComingRead from the app when sent | AvailableBlock, coach or redact before it leaves |
| A paste | AvailableHeld, checked, then let through or stopped | AvailableChecked before the AI app receives it | Not applicableCovered as part of the prompt |
| A file upload or attachment | AvailableDocuments read on their content | CoachedDragged-in files; blocking on request | AvailableAttachments read on their content |
| An image or screenshot | By typeCoached as an image; reading text in it is coming | ComingPlanned with text reading | ComingPlanned with text reading |
macOS and Firefox are coming. File-level enforcement on Windows, which stops a protected file being opened by an AI app, is available on request.
Discover
Every AI tool in use across your Windows computers, who used it and how.
AI websites in use
Every visit to a catalogued AI site, by person and device.
Work or personal account
Which account was used on ChatGPT, Claude, Gemini, Copilot, Perplexity and more.
Desktop AI apps
Installed and running AI apps, and which AI services they connect to.
AI command-line tools
Claude Code, Codex, aider, Gemini CLI and others, found from how they run.
Browser extensions and IDE plugins
AI extensions in browsers and code editors, with risky permissions flagged.
Local AI models
Runtimes such as Ollama and LM Studio, the models present, and any exposed to the network.
New AI tools, found for you
Unknown sites that call an AI service are queued for you to review.
Your approved list
Mark each of more than 70 catalogued tools as approved or not approved, for your organisation.
AI inside other apps and the OS
AI features embedded in SaaS, Windows Recall and Copilot settings.
Identify
What kind of data is going into AI, judged on the computer before anything is sent.
Personal data
E-mail addresses, phone numbers, payment cards, IBANs and ID numbers, with more ID formats being added.
Credentials and secrets
API keys for cloud and AI providers, private keys, tokens and connection strings.
Bulk and structured data
Exports and spreadsheets full of customer records.
Your own source code
Code matched against your repositories, using fingerprints rather than the code.
Your keywords
Project code names, customer names and internal hostnames you list.
Sensitivity labels
Microsoft Purview labels on Office documents and PDFs.
An on-device AI classifier
Health, financial, HR, legal and source-code content recognised by a model that runs locally. English today.
Documents read on content
Word, Excel, PowerPoint, PDF, RTF, OpenDocument, e-mail and notebooks.
Text in images
Reading the text in screenshots and photos, on the device.
Act
Rules that coach first and block when you are ready, in your own words.
Coach, block or log
Per rule, per group, per app, per account type, per data type or label.
A reason when people go ahead
Coaching asks why, and the answer is recorded with the incident.
Coaching before blocking
A rule can only block after a coaching period, or with a reason your admin records.
Try a rule on the last 30 days
See what it would have caught before you switch it on.
One-click modes and a pause
Move a rule between log, coach and block, or pause everything during an incident.
Your words on screen
Edit every coaching and blocking message people see.
Keeps working offline
Devices keep the last policy they received, and never lock people out if something fails.
Local AI gateway
Coding agents and CLIs are checked like a browser tab, and can redact before sending.
MCP gateway
Tool results checked, secrets stripped from tool calls, destructive actions confirmed.
Deny lists for your gateway
AI apps that are not approved, exported for your web gateway, AppLocker and Microsoft Purview.
File-level enforcement
Stop protected files being opened by AI apps on Windows.
Agents and connections
What AI has been connected to, and what it is allowed to do.
MCP servers
Every MCP server configured in Claude Desktop, Claude Code, Cursor, VS Code, Windsurf and Codex.
Agents running unchecked
Coding agents started with their permission checks switched off.
AI keys left in files
Provider, path and the first four characters, never the key.
AI apps with access to Microsoft 365
OAuth grants to AI apps, with an alert when a new one appears.
Agents reaching internal systems
AI tools connecting to your internal hosts, flagged as high risk.
Rules for connections
Allow, coach or block by server, key, extension, agent mode or runtime.
Agent guardrails
Limits on the files, credentials and installs an agent may touch.
Investigate and report
From alert to answer, with evidence that shows what happened and never what was typed.
Incidents
Each case from alert to closure, with the chain of events and redacted evidence.
Alerts where you work
E-mail, Microsoft Teams and Slack, with digests and de-duplication.
Your SIEM
Export to Microsoft Sentinel, Splunk or any SIEM, as JSON or CEF.
AI summaries, your provider
Incident summaries and a weekly digest, using the AI provider you choose, over redacted data only.
Ask in plain English
Questions about your AI use answered from your data, with every query shown.
A report for the board
A PDF of AI use, risk, trend and coaching results, on demand or on a schedule.
ISO/IEC 42001 evidence
Records organised the way an AI management system audit asks for them.
Privacy and security by design
Built so that the privacy conversation is short, and the product is hard to misuse.
No keystrokes, no screenshots
Nothing is read while people type. Browsing outside AI tools is not recorded.
Content stays on the device
By default only labels, counts and hashes are sent, never what was typed or pasted.
A notice before any device enrols
Your monitoring notice is required first, with templates for GDPR and works councils.
Retention you choose
Set how long events are kept, and they are really deleted.
Everything signed
Agents, extension, models and policies are signed and checked before use.
Device certificates
Each device enrols with its own certificate; a revoked device cannot report.
Tampering made visible
Removing protection raises an alert, and uninstalling needs your token.
Roles and an audit log
Viewer, analyst, admin and owner, with every admin action recorded.
A database per customer
Your data kept apart from every other customer, hosted in the EU at launch.
See how it compares.
Thirty controls, set against seventeen security products.