Recce · AI Security Lifecycle

Security at every
stage of the AI
lifecycle.

From model creation to production runtime, Recce applies controls at every stage — nothing serves that hasn't cleared its gate.

Six Stages

Build → Ingest → Test → Deploy → Run → Monitor.

Each stage has a security gate. Each gate writes an event to Band D. No stage is skipped — the lifecycle is the control.

01
Build

Build

Before a model enters the pipeline, its origin, composition, and dependencies are fully documented. AIBOM is generated and the artifact is cryptographically signed.

AIBOM generation
Provenance attestation
Cosign artifact signing
Dependency inventory
Cosign / Sigstore AIBOM generator Band A
02
Ingest

Ingest

All data assets — documents, embeddings, datasets — pass through malware and PII checks before entering the vector database. Only clean, signed assets proceed.

Malware scan (ClamAV)
PII detection & redaction
Data asset signing
Vector DB security gate
ClamAV PII Scanner Milvus Band B
03
Test

Test

Automated adversarial testing runs before any model is approved for deployment. Garak probes cover injection, jailbreak, encoding attacks and agent abuse scenarios.

Garak adversarial probes
Prompt injection coverage
Jailbreak & persona
Red team findings report
Garak NeMo Guardrails Band C
04
Deploy

Deploy

The OPA promotion gate is the final check before production. Only models with a valid Cosign signature, clean CVE scan, and no open critical findings are promoted.

OPA promotion gate
Cosign signature verification
CVE gate (no critical)
Registry promotion
OPA Cosign Band A
05
Run

Run

At runtime, every prompt and API call passes through NeMo Guardrails and the OPA policy engine before reaching the model. Agents operate within per-session tool scopes.

NeMo runtime guardrails
OPA per-call policy
Agent tool allow-list
API access control
NeMo Guardrails OPA Band C
06
Monitor

Monitor

Every event across stages 01–05 streams into Band D. Model drift is monitored continuously. SIEM export delivers a structured telemetry feed to your SOC in real time.

Immutable audit log
Model drift (Evidently AI)
SIEM / SOC export
Compliance scorecard
Evidently AI Splunk / Sentinel Band D
Get Started

Map Recce to your AI pipeline.

Request a technical walkthrough — we'll show exactly where Recce controls attach to your existing model and data workflow.