Recce · Architecture

Technical
architecture
reference.

Component layers, integrations, and deployment topology for engineering and security teams evaluating Recce.

System Diagram

How Recce is structured.

Four control bands sit above the platform layer. A shared policy core connects them. Band D collects telemetry from all three and pushes to external SIEM.

AI Intake Recce Policy Core AI Workloads BAND A Model Supply Chain ModelScan · AIBOM · Cosign · OPA Trusted registry BAND B Data Ingestion ClamAV · PII scan · Signing Milvus vector gate BAND C AI Guardrails NeMo · OPA · Garak Prompt · API · Runtime BAND D Security Telemetry Audit log · Evidently AI SIEM / SOC export Recce POLICY CORE Policy-as-code (OPA) Identity & access control Cryptographic signing plane Audit event router → Band D Model serving Applications APIs & services Agentic systems Edge / on-prem telemetry → Band D → SIEM / SOC
Component Layers

Every component, where it fits.

Recce is composed of purpose-built components that replace or wrap existing open-source security tooling.

Band A — Model Supply Chain
ModelScan
CVE & vulnerability detection in model files
AIBOM Generator
AI Bill of Materials generation & attestation
Cosign / Sigstore
Cryptographic signing & verification
OPA Gate
Policy enforcement at promotion time
Model Registry
Trusted artifact store with provenance
Band B — Data Ingestion Security
ClamAV
Malware scanning on all ingested documents
PII Scanner
Sensitive data detection & field-level redaction
Data Signing
Per-asset signing before vector DB ingestion
Milvus Gate
Vector DB admission control for clean assets only
Band C — AI Guardrails
NeMo Guardrails
Prompt and output safety rail enforcement
OPA Runtime
Per-call policy engine for inference requests
Garak
Automated adversarial red-team probes
Tool Allow-List
Per-session agent tool scope enforcement
Output Classifier
Post-generation policy compliance filter
Band D — Security Telemetry
Audit Log
Immutable, tamper-evident event store
Evidently AI
Model drift & data quality monitoring
SIEM Exporter
CEF/LEEF formatted telemetry push
Compliance Reporter
Scorecard generation against mapped frameworks
Integrations

Works with your existing stack.

Recce integrates with the tools your security, platform, and AI teams already use — without requiring you to swap infrastructure.

Splunk
SIEM telemetry export in CEF format via HTTP Event Collector
Band D
Microsoft Sentinel
Log Analytics workspace ingestion via CEF/LEEF connector
Band D
IBM QRadar
Event log forwarding with LEEF format for AI security events
Band D
Elastic / ELK
Audit log shipping to Elasticsearch for custom SIEM builds
Band D
Milvus
Vector database integration for Band B security gate enforcement
Band B
Cosign / Sigstore
Cryptographic signing and verification for model artifacts
Band A
OPA (Open Policy Agent)
Policy-as-code enforcement across Bands A, B, and C
All Bands
NeMo Guardrails
Prompt and output safety policy enforcement (Band C)
Band C
NVIDIA NIM / Triton
Model serving integration for runtime guardrail attachment
Band C
Evidently AI
Model drift and data quality monitoring for Band D telemetry
Band D
ClamAV
Malware scanning engine for Band B document ingestion pipeline
Band B
Rancher / SUSE
Kubernetes platform integration — cluster-level deployment support
Platform
Get Started

Ready to evaluate the architecture?

Request a technical session with the Recce team. We'll walk through the full component diagram against your existing infrastructure.