Lum Open the app

Don’t trust us. Check.

Most AI reads everything you type. Lum can’t — and you don’t have to take our word for it. Type a secret below and watch exactly what leaves this device.

1 · Type something private
On your device plaintext · never sent
What left your device all the server ever sees

The ciphertext is AES-256-GCM, encrypted with a key generated on this device that the server never receives. The signed receipt is content-blind: it proves your soul was stored, at a time, without revealing a byte of it — and its signature is verified right here in your browser.

2 · Cut the network. Lum still answers.

The app shell, the living mark, and the reply path are all cached and run on-device. When the internet is gone, your AI isn’t.

3 · What a proof here does — and doesn’t — mean

“Proven” on Lum is a precise, narrow word. It means a claim is re-checkable: you can re-run it and get the same answer, and a signature ties the result to who produced it. It is not a claim that an answer is true, wise, or safe. Here is exactly where the line falls.

What the proofs cover
  • Reproducibility — the same input and code give the same bytes, on every backend.
  • Integrity — a signed receipt binds a result to its author and cannot be edited unnoticed.
  • Privacy — what leaves your device is ciphertext; the receipt reveals no content.
  • Provenance — a capsule’s record, lineage, and grade re-derive from signed data.
What they do not cover
  • That an answer is correct, wise, or good advice.
  • That a model has no bias or blind spots.
  • That a certified capsule is safe for a high-stakes use it wasn’t graded for.
  • Anything about a copy running off the platform, where we can’t meter or check it.

Every claim here is machine-checkable. The verifier and client crypto are open; a stranger can re-run the receipt and get the same answer. That’s the whole point.