LUMEN
EN FR ع

Security architecture

Authority never travels down the chain.

Every clinician's clone acts with its human's authority and never a millimetre more. A question can cross the whole hospital, clone to clone to clone. What comes back is an answer each human was entitled to give. What never comes back is privilege.

Asks

The nurse's clone

Asks onward

The attending's clone

Answers

The pharmacist's clone

A chain of clones carries questions across the hospital. It carries authority nowhere.


Scroll
Security architecture
Security architecture

The two invariants

Everything on this page exists to keep two sentences true.

Invariant 01

Authority is inherited and never exceeded.

A clone's authority is a strict subset of its human's, at every instant, on every path, including every clone-to-clone path and every chain of them. There is no mechanism by which a clone obtains information its human could not have obtained.

Invariant 02

Authority never travels down a chain, only answers do.

A clone gains nothing by asking. It receives an answer the other clinician was entitled to give, and nothing more: no accumulation, no transitive privilege, no path by which a chain of clones surfaces something none of their humans could have seen.

Both are made true by mechanism, not by intention. The mechanism is below, and it is deliberately boring: a deterministic check that a reviewer can attack.

The five predicates

Five conditions admit a message. All five, every message.

Before any clone answers any other clone, one check runs. It is a conjunction of five predicates: no score, no model, no learned input, and no exception path.

ADMIT = P1 and P2 and P3 and P4 and P5
  1. P1 · Edge

    The relationship exists.

    A live, named relationship between the two clinicians must exist in the hospital's own graph, and the message must cite the exact one. The message does not get to choose; it must cite the edge the graph agrees on, and a mismatch is a security event.

  2. P2 · Class

    The request class is permitted.

    Each relationship permits specific kinds of requests. A relationship that carries a scheduling question does not thereby carry a prescription question.

  3. P3 · Urgency

    The urgency is within its ceiling.

    Claimed urgency is capped per relationship. Above the ceiling it is clamped, the clamp is written to the audit chain, and the requester is told. Urgency inflation is visible and attributable to a person, never silent.

  4. P4 · Time

    The relationship is valid at this hour.

    Rosters change at 08:00 and the clone's scope changes at 08:00. Outside the validity window, only a recorded delegation that itself passes the first three predicates can carry the message.

  5. P5 · Subject

    Both sides hold a lawful basis for the patient.

    If a patient is named, both clinicians must hold a lawful care relationship with that patient at that moment, or a purpose clinical governance has pre-approved for the class, or a break-glass authorization completed by a human. A human breaks the glass. A clone never does.

Deterministic.

Given the message and the graph snapshot it cites, the decision reproduces byte for byte, forever. That is what makes a regulator's reconstruction possible.

Never learned.

The layer that learns who answers fastest can never write a permission, and the authorization check never reads a learned weight. The two layers are separated in both directions.

Fails closed.

A missing edge, a stale scope, an unresolvable role: every one of them produces a decline, never a default allow.

The audit chain

Every exchange writes its receipt.

The only question a regulator asks is who did this. The record answers with two names, the human and the clone acting for them, and with everything the decision touched.

Anatomy of one chain entry

Askerthe requesting clinician, and their clone
Askeethe answering clinician, and their clone
Question classwhat kind of request this was
Scope checksthe authority decision at send and at receipt
Gate decisioninterrupt, queue, or decline, and why
Human interruptedwhether a person was actually disturbed
Provenancewhere the answer's facts came from
Signaturethe human authorship of the decision
  • Append-only and hash-chained, rooted in the hospital's own hardware security module. Not our servers. The hospital's.
  • Replay is verified end to end before any buffered entries are accepted back into the chain.
  • A gap or a mismatch is itself an audited event. A hole in an audit chain is indistinguishable from tampering, so the chain is built to make holes loud.
  • Portable. The hospital can hand the chain to a regulator, or take it to a successor vendor, without asking us.
No known defence makes prompt injection impossible. The design assumption is containment, not prevention. An injection can make a clone ask a stupid question. It cannot make a clone exceed its human's authority.
The LUMEN security architecture, on its own limits

Injected text never reaches the authorization path, because free text is never an input to an authorization decision. Authority lives in the message envelope, checked by the five predicates; the payload can be as persuasive as it likes.

The floor under the invariants

Four facts the rest stands on.

Keys

The hospital holds them

Key custody is hardware-bound and hospital-held. No vendor, including us, holds the keys to the hospital's brain.

At the bed

Redaction before transmission

Speech is transcribed and redacted on the bedside device, before anything leaves the room. What was never transmitted can never leak in transit.

In transit

Post-quantum hybrid

Inside the hospital's own fabric, transport runs TLS 1.3 with hybrid key exchange, classical plus post-quantum, so a record written in year one is not harvested against a later computer.TLS 1.3 · X25519 + ML-KEM-768

The decision

A human signs

Nothing enters the record unsigned. The clone drafts, chases, and briefs; the clinician owns the decision. This rule never bends, anywhere in the architecture.

Responsible disclosure

Found something? We answer.

Our security contact is published at /.well-known/security.txt on this site. Reports are read by people, not a queue.

Contact security Read the sovereignty page