v1.14.0 · Steer it mid-turn

The AI coding agent leadership can actually approve.

LUCID Agent IDE lets your teams code with AI while your source, prompts & CUI never leave the host. A prompt-injection gate on every tool call that cannot fail open, per-model cost showback, sovereignty-aware governance, Remote to drive your desktop agent from your phone, Voice mode to put it down and talk to it, the LUCID Trainer to teach it the job, and now Fleet Mode: many gated agents at once, each on its own repo and model, every reply scanned. Bring any model.

3,100+ testsmetadata-only by constructionsovereignty-aware & air-gappableany model, no lock-in
0
Tests passing
0
Bytes of code that leave
0
Models in the picker
0
Ways to fail open
Raw models & clouds at the bottom, one neutral fail-closed gate in the middle, only metadata-only evidence rising to your BI at the top.

01 Start here · v1.14.0

Download. Install. Run. No GitHub required.

Built for managers and non-developers: one button per platform, plain-English steps, and zero prerequisites. Bun and the Unicode scanner are already inside the app - it even works air-gapped.

Windows 10 / 11

Windows

Recommended: the installer. Portable option if you can't install software.

Download for Windows
Simple install steps
  1. Click Download for Windows.
  2. Open the downloaded LucidAgent-Setup.exe.
  3. If Windows SmartScreen appears: More info → Run anyway.
  4. Finish the installer, then launch Lucid Agent from the Start menu.
  5. Pick a role and connect Claude, ChatGPT, Gemini, or an API key.
Portable version (no install)
Download LucidAgent-portable.exe, double-click, run. Nothing is written to Program Files.
macOS 12+

macOS

Apple Silicon (M1/M2/M3/M4) primary. Intel package one click away.

Download for Mac (Apple Silicon)
Simple install steps
  1. Click Download for Mac.
  2. Open the .pkg and click through Install → Applications.
  3. Open Lucid Agent from Applications (or Spotlight).
  4. If macOS blocks it (unsigned build): right-click the app → OpenOpen again, or System Settings → Privacy & Security → Open Anyway.
Intel Mac, zip, or Homebrew

Intel .pkg · zip bundles: arm64 / Intel (drag to Applications).

Homebrew (technical users):

brew tap mlcyclops/lucid https://github.com/mlcyclops/lucidagentide
brew trust --cask mlcyclops/lucid/lucidagentide
brew install --cask lucidagentide
Linux x86_64

Linux

Portable AppImage - no package manager required.

Download for Linux
Simple install steps
  1. Click Download for Linux.
  2. Make it executable: right-click → Properties → Allow executing file as program, or run chmod +x LucidAgent-x86_64.AppImage.
  3. Double-click the file to run. No install step.
.deb / .rpm packages
Also published on each release: .deb (amd64) and .rpm (x86_64) for Fedora/RHEL-family distros.

Links always point at the latest successful release (currently v1.14.0). Direct file downloads - you never need a GitHub account.

02 See it in action

Trust what you can verify.

Short walk-throughs of the features that make LUCID the choice for regulated and secure environments.

Coming soon
LUCID · SECURITY

Fail-closed gate

Hidden Unicode blocked before a byte hits disk.

Coming soon
LUCID · REMOTE

LUCID Remote

Scan a QR, open your phone browser, drive the desktop agent.

Coming soon
LUCID · GOVERNANCE

Cost & Savings Ledger

Per-model spend and cache-savings showback in one pane.

Coming soon
LUCID · PROVENANCE

AI-authorship ledger

Which model wrote which lines - per repo and identity.

Coming soon
LUCID · MODELS

Model picker & Claude Fable 5

47 models, OAuth or API key, including Claude Fable 5.

Coming soon
LUCID · WORKSPACE

Preview tabs & device viewports

Yours / Agent tabs plus phone and tablet frames.

Coming soon
LUCID · KNOWLEDGE

KG Packs & RAG

Ground any model on your vault - scanned and local-first.

Coming soon
LUCID · ONBOARDING

Role onboarding

Developer, Security, Manager, Executive - tailored first run.

Short product walkthroughs are being filmed now - posters above mark the first eight cuts.

03 The business case

Your teams already want AI coding. This is how leadership says yes.

Adoption isn't the question, governance is. LUCID turns "we can't let AI touch that codebase" into a program you can fund, defend, and audit: nothing sensitive leaves, injection can't win, spend is visible, and the evidence belongs to you.

Data protection

Nothing sensitive ever leaves

Metadata-only by construction. Source code, prompts, and CUI never leave the host. The allow-list is an architectural guarantee, not a checkbox. A whole class of data-spill risk is designed out.

Threat defense

Injection can't trick your agent

A prompt-injection gate runs on every tool call and cannot fail open. With roughly half of AI-generated code carrying a vulnerability on first review, security is the default, not a toggle.

Cost governance

Govern and prove AI spend

Live per-model spend and cache-savings showback across every provider. When most enterprises overrun their AI budget, leadership gets one number instead of four consoles.

Compliance

Sovereign, air-gap, ATO-ready

CUI isolation, a foreign-origin warning wall, and the AskSage accredited gateway (FedRAMP High, IL5/IL6). Every run doubles as audit evidence suited to CMMC and continuous monitoring.

Portability

No model or cloud lock-in

Bring any model; publish evidence into your own BI. Every new tool your teams adopt increases LUCID's value instead of trapping your data in someone else's console.

Accountability

Know who wrote every line

A tamper-evident ledger attributes which model wrote which lines, per repo, per person, per session. AI spend and AI authorship, both auditable.

Budget isn't the blocker. Governance is.

LUCID is the neutral layer that lets leadership prove value, stay portable, and prove accountability across every AI tool, model, and cloud your organization runs. The alternative is four vendor consoles and no total.

Four consoles and no total → one pane, consolidated into your own BI.

Where the market is going

The AI-coding wave is here. The governance gap is the opening.

Nearly every developer now uses or plans to use AI coding tools, but spend is overrunning, trust in raw output is falling, and every provider wants your cost and audit data in their console. LUCID sits above the tool war: neutral across models and clouds, handing the evidence back to you.

$27B
AI coding-tools market by 2030 (~28% CAGR)
73%
of enterprises exceeded their AI budget
~48%
of AI-generated code has a vuln on first review
84%
of developers use or plan to use AI tools

Industry context (FinOps Foundation 2026; Precedence / Fortune BI; Stack Overflow / GitHub). Figures cited for landscape, not LUCID performance claims.

04 What makes it novel

Twenty-two things you rarely find together.

Plain language below. The deeper “how” stays proprietary.

New in 1.14

Steer it mid-turn

Type while it works and your note reaches the model at its next tool boundary, marked as your instruction and kept outside the untrusted-content envelope. It changes course without a cancel and restart, so nothing in flight is thrown away.

New in 1.14

Approve once, not forty times

An approval can cover every same-kind request for that worker’s session, so a wide refactor stops interrupting you. Full auto-mode exists, but only behind an explicit risk acceptance, and the injection gate still scans every call in it.

New in 1.14

A browser it drives, and you watch

For pages that block automation it opens a visible browser after per-site egress approval, then works by screenshot, scroll, click and type. Capture is compositor-level, so a locked DOM cannot blind it, and closing the window is a hard stop.

New in 1.14

Dictate from your phone, provably on-device

Phone dictation is offered only when the device can prove the audio never leaves it. Under CUI lockdown the browser-vendor cloud path is refused outright, and hold-to-talk transcribes on your desktop with offline Whisper instead.

New in 1.13.2

Fleet fidelity

A crashed lane revives in place with its memory, lane cards show real diff chips and pasted images, staged prompts drain in order, and every session lands on one reviewable Timeline.

New in 1.13

Fleet Mode

Many gated agents at once, each on its own repo and model. No lane cap: a lane is refused only when the machine holds 90%+ for 30 unbroken seconds, and every worker reply is scanned and trust-labeled.

New in 1.12.1

The LUCID Trainer

It interviews your expert scenario-first, distills every answer through a fail-closed pipeline, and drills the team only from confirmed units. Paste a Position Description and it maps that role.

New in 1.12

Voice mode

A hands-free conversation: it reads replies aloud as it writes them, opens the mic when it stops, and runs fully offline if you want. A spoken turn hits the same gate as a typed one.

New in 1.11.9

LUCID Remote

See and drive your desktop agent from your phone via E2E encrypted QR pairing, behind four independent gates.

New in 1.11.9

Preview & Viewports

Yours and Agent tabs with live snapshots to test responsive layouts on device viewports.

A gate that cannot fail open

If the scanner dies or returns garbage, the gate blocks, never “safe.” A test kills it mid-run and the block still holds.

Runtime containment

Even after bash is approved, the process runs OS-isolated and its network is mediated, a package phoning home over DNS at import time is refused and audited.

Provenance-gated memory

Suspicious or quarantined content can never auto-save into memory. Trust comes from the source, not the caller's word.

Encrypted personalization graph

A private, AES-256-GCM “second brain” the agent learns from you and recalls across sessions, CUI-isolated, exportable to Obsidian.

AI-authorship attribution

A tamper-evident ledger of which model wrote which lines, per repo, per person, per session.

Sovereignty-aware governance

Gov-only lockdown, curated model lists, and a clear warning wall before any foreign-origin model is used.

A cache-stable prompt

Safety layers are byte-identical on every request. Untrusted text enters only delimited, only after the cache point, faster and safer.

An IDE where Save is scanned

Edit and save through the same gate. A hidden-Unicode payload is blocked before a byte lands on disk.

One-command migration

Bring your ChatGPT / Claude / Gemini history in, every message scanned, then distilled into your private graph.

Zero prerequisites

Bun and the Python Unicode scanner sidecar are bundled. Works air-gapped out of the box.

A gov-grade gateway, gated

The AskSage accredited gateway is wired in with a lockdown mode, scanned personas, and answers grounded on your own datasets.

Cost tracking & showback

Live per-model spend and cache savings, know exactly what every conversation costs.

05 Built on oh-my-pi

A thin, principled layer over a fast Rust engine.

LUCID rides omp's releases instead of forking it, everything is added through hooks, custom tools, and the SDK. These are the runtime capabilities it is built upon:

ARCHITECTURE · LUCID OVER OH-MY-PILUCID · security · provenance · memoryfail-closed gateprovenanceencrypted memoryAI-authorshipcost showbackomp runtime capabilitiessubagentsplan modeLSPDAPsessionssandboxingtool-callingmodel routingoh-my-pi (omp)NATIVE RUST ENGINEthin, principled layer · heavy lifting stays in omp's Rust engine · upgrades with omp, no fork
LUCID clamps onto omp through hooks, custom tools & the SDK. The heavy lifting stays in omp's Rust engine.
The architecture in one line: TypeScript on Bun, in-process with omp. The only Python is a pure-Unicode scanner sidecar behind a narrow NDJSON contract, so the fail-closed gate that consumes it can never fail open. Provenance & memory live in an append-only DuckDB store.

06 Security model

One lifecycle, enforced end to end.

Every tool call, every Save, every persona, every imported message walks the same path. Any failure at any stage means block or quarantine, never safe defaults.

01

Scan

Pure-Unicode sidecar finds zero-width, bidi, tag-block, homoglyph & PUA.

02

Decide

scanAndDecide: any scan failure ⇒ block / quarantine.

03

Gate

Runs in-process on every tool call via an omp pre-hook.

04

Contain

Approved process runs OS-isolated; egress is mediated + audited.

05

Label

Closed set: trusted · untrusted · suspicious · quarantined.

06

Promote

Suspicious sources can't enter semantic memory.

07

Export

Invisibles escaped; raw referenced by SHA-256, never inline.

Try the gate

Pick a command; the fail-closed gate scans it before it runs.
lucid, agent shell gate active

$ awaiting input…

07 LUCID Remote Live in v1.11.9

Your desktop agent, in your pocket.

The headline of v1.11.9: scan a QR from the Share panel, open your phone browser, then watch or drive the same desktop session through an installable Progressive Web App (PWA). No App Store download. Every prompt still executes on the host behind its fail-closed gate. Remote adds reach, not risk.

See the phone experience

The phone experience, in plain English

A website that behaves like a phone app.

A Progressive Web App (PWA) is a secure website designed to feel like an installed mobile app. Open the QR invite in Safari or Chrome, sign in, and use LUCID Remote immediately. You can optionally save it to your phone's Home Screen for one-tap access.

  • No App Store: nothing to search for, purchase, or install.
  • Watch live: see the transcript, thinking, tools, and new updates.
  • Drive securely: send a prompt or stop the agent from your phone.
  • Desktop stays in control: work runs on the host and passes every LUCID security gate.
LUCID Remote mobile sign-in screen with Google sign-in and an end-to-end encrypted connection notice
1. Open the secure inviteSign in with Google, then the encrypted room key connects the phone to your desktop session.
LUCID Remote mobile session showing live agent updates, tool activity, message composer, Stop and Send controls, and Live you can drive status
2. Watch or drive the agentFollow live work, send the next instruction, or stop the run while the desktop remains the execution host.
END-TO-END ENCRYPTED · AES-256-GCM Agent Phone Desktop 01 · IDENTITY Google sign-in Rendezvous admission 02 · ENCRYPTION Room key Never reaches server CLOUD RELAY Ciphertext + metadata only 03 · AUTHORITY Write token Edit or view-only 04 · HOST GATE Fail-closed Every action re-checked
Phone to desktop through four independent gates over an encrypted channel. The relay sees ciphertext only.
1

Google sign-in

A verified Firebase ID token admits the phone to the rendezvous, and nothing more. Signing in doesn't grant access to anything yet.

2

Room key

An AES-256-GCM key rides only in the invite link's fragment and never touches a server. Without it, the phone can read nothing.

3

Write token

Sending a prompt needs a separate write token carried only by an edit link. A view link stays read-only, refused host-side.

4

Desktop gate

Every remote action still runs on the desktop through its fail-closed scanner, exec approvals, and egress policy. Nothing is bypassed.

The guarantee: a compromised host, CDN, or relay sees ciphertext and metadata, never your session content. Watch the whole turn live (thinking, tool chips, subagents, and the streamed answer) on a mobile-first, installable Progressive Web App that runs the same collaboration core as the desktop, so remote is never a separate, weaker path. Self-host the rendezvous or use the hosted Cloud Run option (claims-gated for the paid Remote Access tier). ADR-0226 / 0227 + 0240–0242 · P-REMOTE.1–.10

08 Voice mode Live in v1.12.0

Put it down and talk to it.

The headline of v1.12.0: press Ctrl/⌘+G and LUCID becomes a hands-free conversation. It reads each reply aloud as it writes it, opens the mic the moment it stops speaking, and a few seconds of silence sends your turn. Your spoken words are scanned on send exactly like anything you typed, and the entire loop can run offline on your own machine.

LUCID Agent [Voice] SPEAKING
The LUCID Agent [Voice] panel. A real spectrum analyser of the agent's own speech, not a decorative animation: log-spaced bands, fast attack and slow release, hanging peak caps. It lives as a mini strip in the prompt bar, or pops out to a panel you drag and anchor anywhere.
New in 1.12

Hands-free turn-taking

Reply finishes speaking, the mic opens, a longer silence sends. It waits for the audio to actually finish, not just the text, and asks for echo cancellation explicitly, so it can never hear its own voice. A manual mic stop never auto-sends.

New in 1.12

Talks after one sentence

The streaming answer is chunked on sentence boundaries and spoken a span at a time, so a long reply starts speaking in about a second instead of twenty. An unterminated code fence is withheld, so it never reads raw source at you.

New in 1.12

Answers built for the ear

Hands-free, the agent gets standing per-turn guidance: lead with the answer, two or three plain spoken sentences, no headings, lists, tables or file paths. It constrains the answer's shape, never the work behind it.

New in 1.12

It keeps you company

Eyes-off, a long turn used to be dead air. Now you get short, escalating spoken acknowledgements while it works, capped per turn and never spoken over the answer itself.

ElevenLabs your cloned voices ChatGPT · OpenAI 13 voices Kokoro offline, on your machine Whisper bundled on-device dictation

The picker sits in the composer, remembers a voice per engine, and greys out any engine that isn't actually configured with the reason why - including the one that catches people out: an OpenAI subscription sign-in cannot reach the platform speech API.

Same gate, same rules: a transcript is ordinary user input and is scanned on send like anything typed. A cloud voice engine is ordinary egress you opt into per engine, and auto-speak is off by default. Pick offline Kokoro to speak and the bundled, SHA-256-verified on-device Whisper to listen, and the whole conversation stays on your machine: air-gap safe, no key, no audio leaving the box. ADR-0247 / 0248 / 0249 · P-VOICE.2–.6

09 The LUCID Trainer New in v1.12.1

Teach it the job. It proves it learned.

The headline of v1.12.1: a brain icon on the rail opens an immersive knowledge-extraction stage. LUCID interviews your subject-matter expert scenario-first, chases the exceptions with capped five-whys follow-ups, and never re-asks confirmed ground. Nothing an expert says is trusted on arrival: every answer survives a fail-closed pipeline before it is stored, and only a confirmed teach-back promotes it.

01 INTERVIEW scenario-first 02 DISTILL fail-closed pipeline 03 TEACH-BACK confirm = promote 04 DRILLS confirmed units only A TRAINEE MISS RE-OPENS EXTRACTION
The Trainer flywheel. Every answer is redacted, scanned, distilled inside untrusted delimiters, and re-scanned before storage; the expert's teach-back confirmation is the only promotion, and drills draw from confirmed units alone. A trainee miss loops straight back to extraction.
New in 1.12.1

Scenario-first interview

It asks how the work actually happens, walk me through the last time, then chases the edges with capped five-whys follow-ups. Confirmed ground is never re-asked, so every session moves the map forward.

New in 1.12.1

Distilled, never trusted raw

Every answer is PII-redacted to typed placeholders, scanned, distilled by your configured model inside untrusted delimiters, then re-scanned. It lands in storage labeled untrusted, and stays there until proven.

New in 1.12.1

Teach-back is the promotion

LUCID plays the knowledge back; the expert confirms or corrects. Confirmation is the promotion, nothing else moves a unit to trusted. A live coverage HUD tracks L0-L3 per domain, so the gaps stay visible.

New in 1.12.1

Drills from confirmed ground

Next-step, spot-the-exception, and sequence drills are generated only from confirmed units, never from raw notes. A trainee miss re-opens extraction, so the map heals where it actually failed.

Role-generic by design: paste a Position Description or a task list and it builds the coverage map for that role, a fresh install simply asks what yours is. A wealth-management-ops pack ships as a labeled sample, and the new LUCID Agent role wraps it all in an immersive persona: talking mascot, cinematic boot, hands-free flow.

Fail-closed before storage: the pipeline runs before a byte is persisted, and any failure at any step leaves the answer untrusted, never a safe default. Drills can only be generated from units the expert has confirmed, so a hallucinated "fact" has no path into training material.

10 Fleet Mode New in v1.13

One agent was the demo. The fleet is the workday.

The headline of v1.13: run many gated LUCID agents at once, each in its own repository folder and on its own model, streaming into its own live mini window inside one movable dashboard. The orchestrating session sees lane metadata only, never lane text, and every worker reply passes the same fail-closed gate as your own typing before anything reads it.

ORCHESTRATOR metadata only lane · api repo-a · claude · working lane · web repo-b · gpt · awaiting you lane · etl dev.azure.com clone · needs approval ADMISSION burst (a compile spike) = free 90%+ held 30s straight = refused, with the measured % and duration
The fleet fan-out. Each lane is its own gated LUCID engine on its own repo and model; the frame colour is the status (working, awaiting you, needs approval - approvals are fail-closed, silence is a deny). Lanes are unlimited; only sustained machine pressure refuses one.
New in 1.13.1

Unlimited lanes, honest refusals

The old cap is gone. A lane is refused only when CPU or memory holds 90%+ for 30 unbroken seconds, so a compile spike never blocks you, and the refusal names the measured percent and how long it held.

New in 1.13.1

Lanes straight from a repo URL

Paste a GitHub, GitLab, or Azure DevOps remote (https or ssh) and the lane clones it into the folder you picked in the real OS dialog and goes to work; an existing clone is reused.

New in 1.13.1

Tokens scoped to their host

A private-repo token lives in the OS-encrypted vault under the host you typed it for, rides an auth header (never the URL, never .git/config), and is never offered to a different host.

New in 1.13.1

A minimized HUD that tells the truth

Collapsed to the status bar, the fleet shows one colored dot per lane state with counts, needs-approval first; hover a dot and it names the lanes. You always know which agent is blocked on you.

New in 1.13.2

Lanes that survive

The lane turn clock is gone: a mid-turn crash surfaces in milliseconds, and error is recoverable. Retry re-sends the last prompt; Respawn revives the lane in place with its memory. An approval open at death dies as a deny.

New in 1.13.2

Diff chips & pasted images

A worker's edit renders as a one-line chip - filename, green +N / red -N - expanding to the hunk. Paste a screenshot into any lane composer and it rides the prompt as a real image block.

New in 1.13.2

Staged prompts

While a lane streams, Send flips to Stage: park your next thoughts as numbered chips (reorder, remove, cap 8) and they run in order when the lane goes idle. One turn per lane is never crossed.

New in 1.13.2

The Timeline

Every session this machine has had - chats, fleet lanes, imports - across every workspace, day-grouped and newest-first. Click a row and the transcript expands in place. Read-only by design.

New in 1.14

Approve once per session

A lane’s approval can cover every same-kind request for the rest of that session, so a wide refactor stops asking you forty times. A deny is never remembered.

New in 1.14

Full auto-mode, risk accepted

Per lane or fleet-wide, behind a warning you must accept: the server refuses to enable it without that acknowledgment. The injection gate still scans every tool call, and auto grants stream as visible chips.

New in 1.14

Check in without interrupting

Ask a busy lane what it is doing and get elapsed time, current phase, pending tool calls and queue depth from live state, plus a one-click nudge the agent answers at its next tool boundary.

New in 1.14

Drive lanes from your phone

The phone app now lists lanes with a name filter and can prompt, stop, or answer an approval on any of them, edit-gated on the host as well as the client.

Same gate, multiplied: every lane is its own gated engine, every worker reply is scanned and trust-labeled before the orchestrator reads it, and every permission ask surfaces to a human with silence as a deny. Scaling out never relaxes a single rule.

11 Any model, any provider

Bring whatever you already pay for.

Sign in with your subscription (OAuth) or paste an API key, keys live in the OS-encrypted vault, never reaching the renderer or the agent. The gate scans every turn the same way, whichever model you choose.

Anthropic Claude · Fable 5 OpenAI GPT Google Gemini xAI Grok Perplexity Sonar AskSage gov gateway Ollama · llama.cpp · vLLM local
Government

Accredited gov gateway

AskSage routes every turn through GovCloud with scanned personas and dataset-grounded RAG, one lockdown toggle hides direct providers.

Offline

Fully air-gapped

Run U.S. open-weight families on your own hardware with local-first RAG and bundled WASM embeddings, no GPU, no egress.

Showback

Cost & savings ledger

Unified spend across every model, estimated cache savings, hit-rate, and per-session drill-down, built for teams that attribute AI cost.

12 Who it's for

Built for the teams the other tools treat as an afterthought.

Government · regulated · CUI teams

A sovereignty-aware agent with hard CUI isolation, a fail-closed gate, and a full provenance / audit trail, packaged for locked-down, air-gapped laptops with zero prerequisites.

Security-conscious engineers

Every tool call, every Save, every persona, every imported message scanned by a gate that cannot fail open. Prompt-injection defense is the default, not a toggle.

Teams that need governance & showback

Real cost per model with cache-savings showback, plus a tamper-evident ledger of which model wrote which lines. AI spend and AI authorship, both auditable.

Agent-platform builders

A worked, test-backed example of adding security, provenance, and memory around a fast runtime via hooks / tools / SDK, extend, never fork.

13 Field manual

Frequently asked

What is LUCID Agent IDE?
A security-first agentic coding harness. It wraps the oh-my-pi (omp) coding runtime with a fail-closed layer that scans every tool call, contains the runtime, tracks provenance, remembers across sessions, and attributes which model wrote which lines, added entirely through omp hooks, custom tools, and the SDK, never a fork.
What does “fail-closed” mean here?
Any failure to get a valid, clean result (a dead scanner, a malformed response, a timeout, an unknown field) is treated as block or quarantine, never as safe defaults. If the Unicode scanner dies mid-run, the gate still blocks. A test kills it on purpose to prove the block holds.
Which AI models does LUCID support?
Any model omp exposes: Anthropic Claude, OpenAI GPT, Google Gemini, xAI Grok, Perplexity Sonar, the AskSage accredited government gateway, and local open-weight models via Ollama, llama.cpp, or vLLM. Authenticate with your subscription (OAuth) or an API key; every turn passes the same gate.
Is it really built on oh-my-pi (omp)?
Yes. omp is a fast agentic coding runtime with subagents, plan mode, LSP, DAP, hindsight memory, hashline edits, and time-traveling rules, driven by a native Rust engine. LUCID adds its security, provenance, and memory through omp's hooks, custom tools, and SDK, riding omp's releases instead of forking.
Can it run air-gapped or in government environments?
Yes. It ships as a desktop app with zero prerequisites (Bun and the Python scanner sidecar are bundled), runs fully offline with local models and local-first RAG, isolates CUI, and integrates the AskSage accredited gateway with a lockdown mode, designed for locked-down, air-gapped laptops.
What is LUCID Remote?
Shipped in v1.11.9: see and drive a running desktop LUCID agent from your phone's browser. The phone interface is a Progressive Web App (PWA), meaning a secure website that behaves like a phone app and can be saved to your Home Screen, with no App Store download. Pair by QR from the Share panel. End-to-end encryption and four independent gates protect the connection: Google sign-in, a room key that never touches the server, a separate write token, and the desktop's fail-closed gate. The phone shows live updates and lets an authorized user send or stop work; execution remains on the desktop.
What is Voice mode, and does talking to it weaken the security model?
Shipped in v1.12.0. Press Ctrl/⌘+G and LUCID becomes a hands-free conversation: it reads each reply aloud while it is still writing it, opens the mic the moment it stops speaking, and sends your turn after a few seconds of silence. Audio starts after the first sentence rather than the whole answer, so a long reply begins speaking in about a second instead of twenty. Hands-free, the agent is also told each turn to answer for the ear - lead with the answer, two or three plain sentences, no headings, lists, tables, or file paths - which shapes the answer, never the work behind it. Nothing about the security model changes. A transcript is ordinary user input and is scanned on send exactly like something you typed; a cloud speech engine is ordinary egress you opt into per engine; and auto-speak is off by default. Pick the offline Kokoro voice and the bundled on-device Whisper for dictation and the whole conversation stays on your machine - no key, no audio leaving the box, still air-gap safe.
What is the LUCID Trainer, and can a bad answer poison it?
Shipped in v1.12.1. A brain icon on the rail opens an immersive knowledge-extraction stage: LUCID interviews your subject-matter expert scenario-first, chases exceptions with capped five-whys follow-ups, and never re-asks confirmed ground. No answer is trusted on arrival: it is PII-redacted to typed placeholders, scanned, distilled by your configured model inside untrusted delimiters, re-scanned, and stored untrusted until the expert confirms the teach-back, confirmation is the promotion. Drills (next-step, spot-the-exception, sequence) are generated only from confirmed units, and a trainee miss re-opens extraction. Paste a Position Description or task list and it builds the coverage map for that role.
What is Fleet Mode, can it run multiple agents at once?
The headline of v1.13: many gated LUCID agents at once, each in its own repo folder and on its own model, streaming into its own live window in one dashboard. There is no lane limit; a lane is refused only when CPU or memory has stayed at 90%+ for 30 unbroken seconds, and the refusal tells you the measured number and how long it held. Point a lane straight at a GitHub, GitLab, or Azure DevOps URL; the token lives per host in the OS-encrypted vault and rides an auth header, never the URL. Every worker reply is scanned and trust-labeled before the orchestrator sees it, and approvals are fail-closed: silence is a deny.
How do I install without using GitHub?
You don't need a GitHub account. Use the Download section on this site: one button for Windows, macOS, or Linux that starts a direct file download. Follow the short numbered steps under each card (SmartScreen / Gatekeeper / chmod are explained in plain English). The app bundles its runtimes - no Node, Python, or Bun install on your machine.
Why do executives and security leaders choose LUCID?
Because it lets leadership say yes to AI-assisted coding. Nothing sensitive leaves the host (metadata-only by construction), prompt injection can't fail the gate open, AI spend is governed with per-model cost showback, and every run produces audit evidence suited to CMMC and continuous monitoring. It stays neutral across models and clouds, so the cost and governance data belong to you, not a vendor console.
How much does it cost?
The source-available core is free. An enterprise add-on tier (executive BI rollups, SIEM audit export, central policy) is separately licensed and optional, nothing in the core depends on it.

14 From the same workshop

The Tactical GenAI Trainer, newly revamped.

Tactical GenAI Trainer is a training environment for simulating and deploying GenAI capabilities in restricted environments. Its fully generative interface handles dynamic injects live, so operators train against scenarios that adapt as they respond. Built in the same workshop as LUCID, and freshly relaunched.

Tactical GenAI Trainer: the revamped training environment with dynamic scenario injects and a fully generative interface
The revamped Tactical GenAI Trainer: dynamic scenario injects through a fully generative interface.

Deploy an agent that can't be tricked into betraying you.

Download the desktop app, or read the source. Open core, source-available, one increment at a time behind its own ADR + demo + tests.

FAIL-CLOSEDMETADATA-ONLYSOVEREIGNTY-AWAREAIR-GAPPABLENO FORK