Skip to content

Lumina · Risk Metaverse

Lumina drafts.
People sign.

Sastrum's AI layer scopes your risk universe, proposes controls across four pillars and drafts policies with the clauses it relied on. Every suggestion is accepted or rejected by a named person, and logged.

How it works

Six steps, and a person on four of them.

Scope and onboard set the ground. From Suggest onward, every step pairs something Lumina produces with a decision a named person owns.

  1. 01Scope7-step universe builder
  2. 02OnboardCatalogue → repository
  3. 03SuggestControls per pillar
  4. 04DraftPolicy Studio / Factory
  5. 05ApproveFour-stage chain
  6. 06MonitorControl tests, reg watch

Recorded in the product

Lumina, at work.

Drafting policies in batch, proposing controls against a single risk, and drafting one policy with the clauses it cites. Every suggestion is accepted or rejected by a person.

Policy Factory · Batch drafting

Selected risks are de-duplicated by policy archetype, then drafted in parallel. Finished drafts land in Policy Studio for review.Sample organisation

Lumina · AI Suggest Controls

Lumina proposes a control bundle across all four pillars and shows the reasoning behind it. Each suggestion is accepted or rejected by a person.Sample organisation

Policy Studio · Lumina drafting

A governance gap is sent to Policy Studio, where Lumina drafts the policy and the finished draft opens with its purpose, scope, provisions and the framework clauses it cites.Sample organisation

Suggest → Draft → Approve → Monitor

Lumina proposes. A person decides. The record keeps both.

This is the whole of Lumina's authority: it produces drafts and suggestions, and a named person accepts, rejects, edits or signs. The activity log is the evidence an auditor asks for.

StageLumina proposesA person decidesWhat is logged
  1. 03SuggestA cross-pillar control bundle for one risk (governance, technical, people and physical) against the frameworks in scope.Accepts or rejects each suggestion, one at a time.Control accepted · risk · named person · timestamp
  2. 04DraftOne policy drafted against a risk and its gap control, with a reasoning summary and the clauses it relied on. Policy Factory does the same in batches.Edits the draft, then submits it for approval.Policy drafted · drafting rationale stored on the record
  3. 05ApprovePreviewCarries its rationale, the linked risks and the history into every stage of the chain.Maker, Checker, Head of Department and Strategic Director sign in turn.Each stage recorded, with its SLA clock
  4. 06MonitorPreviewTests the controls behind the policy by pillar, and turns a new circular into a triage queue with the policies and controls it touches.Triages what changed and owns the action it raises.Change detected · affected policies and controls listed

Lumina never publishes a policy or accepts a control on its own.

In the product today

Six capabilities you can use now.

Verified in the application on 18 September 2026, with ten AI-drafted policies published and the accept/reject log behind them.

  1. Risk Universe builderIndustry, sector, sub-sector, presence, jurisdictions, frameworks, profile. Lumina prunes the universe to what applies.
  2. Risk Catalog & Repository35 Indian banking risks in six categories, each with inherent and residual ratings and framework drivers.
  3. AI Suggest ControlsA cross-pillar control bundle per risk, against the frameworks in scope. Accept or reject each one.
  4. Policy StudioOne policy drafted against a risk and its gap control, with a reasoning summary and clause citations.
  5. Policy FactoryBatch drafting, de-duplicated by policy archetype; drafts land in the Studio for review.
  6. Copilot Activity logEvery AI action with its risk, outcome and timestamp: the evidence your auditor will ask for.

Bring your own model

Your data. Your models. Your rules.

Choose a routing preset and see how Lumina's tasks are placed. Keys are encrypted at rest and masked on screen; every request emits an audit event.

Your models
Cloud, on-premise or hybrid. You choose what Lumina runs on.
Your perimeter
Per-task routing keeps high-sensitivity work inside your own infrastructure.
Your keys
API keys are encrypted at rest and masked on screen.
Your record
Every AI request emits an audit event.

Security & Trust

Platform · AI Configuration · Task routing

Recommended. High-sensitivity tasks stay on-prem; frontier cloud models handle the rest.

TaskSensitivityPlacement
Policy draftingHighOn-prem
Control suggestionHighOn-prem
Control effectiveness scoreMediumCloud
Dashboard insightsMediumCloud
Semantic embeddingsLowCloud

Providers available in the product

  • AnthropicCloud
  • OpenAICloud
  • GoogleCloud
  • OllamaOn-prem
  • vLLMOn-prem

Placement shown is illustrative of each preset.

Recorded in the product

AI Configuration · Bring your own model

Providers, routing and residency are set per tenant, and each task can be pinned to a cloud or on-premise model.Sample organisation

PreviewPreview · sample data

Where Lumina is going next.

These screens are in the application today with sample data. They appear here with a Preview badge until they run on live tenant data.

  • Executive viewPreviewCompliance PostureA posture view by pillar and framework, with the risk behind each number.
  • GovernancePreviewApproval InboxMaker → Checker → HOD → SD, with SLA clocks and the AI rationale at each stage.
  • OperationsPreviewReal-time Control TestsScheduled tests by pillar and a live event feed.
  • CompliancePreviewRegulatory WatchRegulator feeds turned into a triage queue with the affected policies and controls.
  • GovernancePreviewPolicy ↔ FrameworkEach policy's coverage of each framework, computed from control mappings.
  • What's next

Recorded in the product

Real-time Control Tests

Mapped controls run on a schedule and report back by pillar, each with its own run history, source and current state.Sample organisation

See Lumina draft against your own risks.

The demo opens on a universe scoped to your sector and regulators, and walks the accept, draft and approve flow end to end.