Engineering
Your engine, not ours: running agents on the customer’s model
The fastest way to fail an enterprise security review is to ask it to send source code to your servers and run it through your models. lumaq is not built that way.
lumaq ships the control plane and the worker — not the intelligence. The platform coordinates the work: requirements, blueprints, work orders, verification, approval, feedback. The model that actually writes the code is your choice, running on infrastructure you control. That one decision changes what a security team has to accept before it can say yes.
The worker, not the brain
Most “AI software” products are a thin shell around someone else’s model, hosted by the vendor. That is fine for a demo and a dealbreaker for regulated software. lumaq separates the two: it owns the orchestration; you own the engine. Point it at a hosted model on your own key, or an open-weight model you run inside your network. lumaq never sees the weights, and never trains on your content.
Two paths into one queue
Your engineers already have coding agents they trust — Claude Code, Cursor, Devin. Connect one over MCP and work orders arrive inside it as tools, with their full context attached; the pull request opens under your git identity, in your repository. Prefer not to wire anything up? Run the lumaq worker on your own machines and pull from the same queue. Either way, the intelligence is yours.
The private path
For locked-down environments, lumaq ships as a single image. On the private path, code and documents are indexed on your own machines and never leave your network — and where the requirement is absolute, the model runs inside it too. Air-gapped is not a special edition bolted on later; it is the same system with the boundary drawn tighter.
Governance follows the engine
Because the engine is yours, the controls around it are too. Set model policy once at the org level — allow or block a provider or a single model. See spend by project, user, and model, with budgets and a hard limit that stops new work instead of surprising you at month end. An AI platform should not be a place your IP goes to visit; it should run where your software already runs.