Recce · Security Fabric

One fabric.
Every AI workload.

Four intake bands, one policy plane, one audit trail. Every AI deployment inherits the same controls and writes back to the same telemetry stream.

Architecture

Four bands. One policy core.

Every security event — allow or block — is recorded to the same immutable audit log and forwarded to your SIEM via Band D.

Band A · Model Supply Chain Scan · AIBOM · Sign · Register OPA promotion gate Band B · Data Ingestion Malware · PII · Sign · Vector gate Milvus — clean content only Band C · Prompts & APIs OPA · NeMo · Garak · Runtime Allow / block per call Band D · Observability Audit · Drift · SIEM · SOC Splunk · Sentinel · QRadar · ELK Recce Security Fabric Centralized policy & governance Identity & access control Audit & compliance Encryption & signing Integrated workflows Deployment targets Model serving Applications APIs & services Agentic systems Edge / on-prem telemetry · audit · policy violations → Band D → SIEM / SOC
Band A · model supply chain
Band B · data ingestion
Band C · prompts & agents
Band D · observability
Recce policy plane
Band Detail

What each band does.

Each band targets a distinct attack surface with purpose-built controls, all reporting into the same audit stream.

Band AModel Supply Chain

Model Supply Chain

Governs every model from ingestion through to registration. An OPA gate prevents unsigned or vulnerable artifacts from reaching production.

Model ingestion pipeline
CVE / vulnerability scanning (ModelScan)
AIBOM generation & attestation
Cryptographic signing (Cosign / Sigstore)
OPA promotion gate
Trusted model registry
Explore Band A →
Band BData Ingestion Security

Data Ingestion Security

Intercepts documents and embeddings before they reach the vector database. Malware and PII checks gate every ingest event.

RAG document ingestion pipeline
Malware scanning (ClamAV)
PII detection & field-level redaction
Data asset signing
Milvus vector DB security gate
Signed embedding provenance
Explore Band B →
Band CAI Guardrails

AI Guardrails

Enforces responsible AI policy at the prompt, API and runtime layer using NeMo Guardrails, OPA policy, and continuous Garak red-team coverage.

NeMo Guardrails (prompt/output)
OPA policy engine
Garak red-team coverage
Prompt injection detection
Jailbreak & persona attack prevention
Agent tool allow-list
Explore Band C →
Band DSecurity Telemetry

Security Telemetry

Every policy decision across Bands A–C writes an event here. Drift monitoring, SIEM export, and compliance scorecards give SOC teams continuous visibility.

Immutable audit log
Model drift detection (Evidently AI)
SIEM / SOC export (Splunk, Sentinel, QRadar, ELK)
Real-time policy violation streaming
Compliance scorecard
CEF / LEEF format support
Explore Band D →
Get Started

See the fabric in your environment.

Request a technical walkthrough — we'll map Recce controls to your existing AI stack and show exactly what changes.