From Prototype to Product: The Lumos Audit | NetVerse Insights

From Prototype to Product: The Lumos AI Security & Analytics Audit

Caleb Adoh
Caleb Adoh Growth and Marketing Tech Leader, NetMonkeys
In July 2026, NetMonkeys officially rolled out Lumos AI—our proprietary operational data analytics tool—after months of rigorous prototyping, auditing, and enterprise testing. Here is a technical deep dive into how we built a product that turns siloed business data into instant, verified intelligence.

The Core Problem We Set Out to Solve

Every business knows they are sitting on a goldmine of data. The problem? That data is fragmented across legacy ERP systems, decades-old SQL databases, disjointed CRM platforms, and a labyrinth of unorganised SharePoint folders.

When the generative AI boom hit, companies tried pointing public tools like ChatGPT at these problems, only to face severe data security risks, "hallucinated" numbers, and a complete lack of context. We realised that businesses didn't need another generic chatbot; they needed an intelligent, secure extraction engine. That realisation birthed Lumos AI.

Engineering the Lumos Architecture

From day one, the architecture of Lumos was defined by two uncompromising pillars: Security and Verifiability. To achieve this, we leveraged Microsoft Azure's isolated OpenAI instances combined with an advanced Retrieval-Augmented Generation (RAG) framework.

Here is how the data flow was engineered:

  • Ingestion and Vectorisation: We built automated pipelines that connect to a client's specific databases. Lumos ingests this structured and unstructured data, converting it into mathematical representations (vectors) stored in a secure, isolated vector database.
  • Semantic Search: When a user asks a complex operational question, Lumos doesn't rely on pre-trained global data. It performs a semantic search exclusively against the client's vectorised data vault to find exactly the right proprietary context.
  • Verified Output: The Azure OpenAI model then reads only that retrieved context to formulate its answer, providing explicit citations back to the original internal documents or database rows.

"Lumos wasn't designed to be just another chatbot; it was engineered to be the intelligent connective tissue between a company's data and its decision-makers."

The July Rollout & Rigorous Security Audit

Before any enterprise tool can be deployed, it must survive intense scrutiny. The July rollout of Lumos AI was preceded by an exhaustive security and compliance audit.

Because Lumos handles highly sensitive commercial data—ranging from supply chain logistics to financial forecasting—we integrated it deeply with Microsoft Entra ID (formerly Azure Active Directory) and Microsoft Purview.

This means Lumos inherently respects Role-Based Access Control (RBAC). If a warehouse floor manager asks Lumos for the monthly P&L statement, the system checks their Entra ID credentials, recognises they lack financial clearance, and refuses to surface the data. The AI cannot "leak" information that a user wouldn't normally be able to access in the native system.

Code on a screen representing software development
Prototyping Lumos AI required bridging complex database architectures with secure language models.

From Prototype to Commercial Reality

Taking an AI tool from a working laboratory prototype to a resilient, commercial-grade product is the hardest part of the development lifecycle. It required hardening the APIs, ensuring the vector databases could scale dynamically under load, and designing a user interface that felt instantly familiar to non-technical staff.

The result is a tool that allows a CEO to ask, "Based on last quarter's shipping data, what is our projected supply chain delay for Q4?" and receive an instant, accurate, and fully cited answer drawn directly from their own company's history.

Executive Takeaways

1. RAG is non-negotiable. If your AI isn't using Retrieval-Augmented Generation to read exclusively from your own data, it is guessing. In enterprise environments, guessing is unacceptable.
2. Security must be systemic. Your AI tool must natively inherit the access controls and compliance policies of your existing network architecture.
3. Citations build trust. For staff to trust AI-generated insights, the system must provide clear, clickable citations tracing back to the original source data.

The successful audit and rollout of Lumos proves that enterprise AI doesn't have to be a black box. When engineered correctly, it is the ultimate tool for commercial clarity.

Ready to Audit Your AI Strategy?

Ensure your artificial intelligence initiatives are secure, compliant, and actually driving ROI. NetMonkeys provides expert AI consulting services to help UK businesses build and deploy intelligent architecture safely.