Skip to content

Frequently asked questions

Is Lazurio an AI model?

No. Lazurio is the working environment for company materials and applications. The selected AI client and model provider supply the AI. Review their pricing, security and data terms separately.

Is Lazurio a finished, packaged product?

No. Lazurio is in active development. The supported setup is a public source checkout using Git and Bun, and CLI v0 is experimental. A packaged installation is a future target. Lazurio is currently source-available under FSL-1.1-Apache-2.0; the security and control evidence explains the license and maturity details.

Does Lazurio replace Microsoft Copilot?

Not categorically. Microsoft Copilot is a natural fit for assistance grounded in Microsoft 365. Lazurio focuses on governed, source-controlled work across repositories and tools. Many organizations may use both. See the full comparison.

Can an agent access everything the user can?

It depends on the setup. An agent may use files, accounts and tools available to its running process. OS permissions, the AI tool’s sandbox, the workspace and service credentials determine access. A prompt neither grants new rights nor removes existing ones. Test what should be allowed and what should be denied.

Is all Lazurio data stored locally?

No. Working checkouts are local, while Git repositories, model requests, external applications and deployed modules may use provider infrastructure. Optional hosted Lazurio services add further stores when enabled. The concrete data-flow and processor map belongs to the deployment.

How are secrets handled?

Real secrets stay outside Git in scoped ignored paths or approved provider stores. Tracked files contain only schemas, required variable names and instructions. Endpoint, backup, rotation and incident controls must protect the actual custody location.

What stops an agent from publishing a bad change?

For Git work, branch rules, required checks, reviews and merge permissions can mechanically protect the target branch. Pushing a review branch is still a data transfer to GitHub. Email, chat and other providers need their own permissions and confirmations; explicit authorization is process-only where no provider interlock exists.

Are Organizations isolated from each other on one machine?

They are separate GitHub and repository boundaries, not isolated operating-system environments. One machine is one trust domain. Use separate machines or equivalent infrastructure when a process compromise must not cross company boundaries.

Is Lazurio certified for a compliance framework?

No certification or universal compliance claim is made. Evaluate the actual deployment, providers, controls and legal obligations.

Is there an audit trail?

Git changes can be tied to commits, pull requests, reviews and deployments. Provider and endpoint actions need their own logs. Local file reads and model requests are not automatically logged by Lazurio.

Does the documentation have an MCP server?

Not yet. Agents can use /llms.txt and /content-index.json today. A future MCP server is planned as a read-only view over the same content, not a second source.

Where should I start an IT review?

Start with the ten-minute IT briefing, then test data access and security and deployment and operations against the proposed configuration.