From model creation to production runtime, Recce applies controls at every stage — nothing serves that hasn't cleared its gate.
Each stage has a security gate. Each gate writes an event to Band D. No stage is skipped — the lifecycle is the control.
Before a model enters the pipeline, its origin, composition, and dependencies are fully documented. AIBOM is generated and the artifact is cryptographically signed.
All data assets — documents, embeddings, datasets — pass through malware and PII checks before entering the vector database. Only clean, signed assets proceed.
Automated adversarial testing runs before any model is approved for deployment. Garak probes cover injection, jailbreak, encoding attacks and agent abuse scenarios.
The OPA promotion gate is the final check before production. Only models with a valid Cosign signature, clean CVE scan, and no open critical findings are promoted.
At runtime, every prompt and API call passes through NeMo Guardrails and the OPA policy engine before reaching the model. Agents operate within per-session tool scopes.
Every event across stages 01–05 streams into Band D. Model drift is monitored continuously. SIEM export delivers a structured telemetry feed to your SOC in real time.
Request a technical walkthrough — we'll show exactly where Recce controls attach to your existing model and data workflow.