Security and privacy

Built so the privacy conversation is short.

Classification happens on each computer. Raw content never leaves the device: what reaches Lamplighter is structured evidence, and the schema refuses any field that could carry content.

Privacy by design

What leaves the device, and what never does.

No keystroke logging and no screenshots. A prompt is read when it is sent and a paste when it lands in an AI tool. Browsing outside AI tools is not recorded.

  • A monitoring notice you write is required before any device can enrol, and every user sees it.
  • Evidence is minimised by default. An organisation can choose a short redacted or pseudonymised excerpt, and the change is audited.
  • Retention is yours to set, and deletion is real deletion.
  • A person’s events and findings can be listed for a subject-access request.

What reaches Lamplighter

Class labels and confidences
What kind of data it was, and how sure the device is.
Counts, sizes and hashes
Byte counts, a content hash and a similarity hash; never the content.
A content-free gist
The shape of what was pasted (rows, columns, the kinds of values and how many of each), with no word of it.
File metadata
The extension, the size, a keyed hash of the name and a location class. Never the name or the path.
The decision
The policy that applied, what the person chose to do, and which device and AI tool.

Security of the service

Hard to misuse, and honest about what is still to do.

Everything is signed

Policies, the app catalogue, the on-device model and agent releases carry a signature that each device verifies before use, and a device keeps its last known good copy if a fetch or a check fails.

Device certificates

Each device authenticates with mutual TLS, using a certificate from your tenant's own certificate authority.

Customers kept apart

Every table and every event carries the tenant id, row-level security is enforced on every table, and each customer has its own database.

Secrets sealed

Credentials held on your behalf are sealed with AES-256-GCM under a key wrapped by Azure Key Vault. Secrets the scanners find are never stored: only a provider, a path and four characters.

No passwords

Dashboard access is by invitation, in four roles, through your own identity provider or an e-mailed link with an optional second factor. Every admin action is written to an append-only audit log.

No interception

No TLS interception and no first-party kernel code. The agent fails open: if it cannot decide, work carries on and the device reports that it was degraded.

Still to do, said plainly: an external penetration test is planned with its scope written and has not been performed yet, and Windows code signing is built into the release pipeline and waits on the certificate.

Hosting and sub-processors

Hosted in the EU, with one infrastructure provider.

The service runs in Microsoft Azure, North Europe (Ireland). A tenant is created in one region and its data does not leave it. Thirty days’ notice of a new sub-processor goes to every tenant owner.

Microsoft Ireland Operations Ltd (Microsoft Azure)
Infrastructure: compute, database, key management, storage, networking, logging and outbound e-mail. North Europe (Ireland).
Microsoft Corporation (Microsoft Entra ID)
Sign-in for dashboard users, and directory sync, when your organisation chooses to connect it.

The data processing agreement, the full sub-processor schedule and the privacy impact assessment template are available on request.

Bring your security and privacy questions.

We will walk your team through the design on a real machine.