Recce · Solutions

Security for every
AI surface.

Six security domains. One platform. Whether you're securing a single RAG pipeline or an enterprise AI fabric spanning multiple clouds and platforms.

All Solutions

Purpose-built for each attack surface.

Each solution maps to one or more Recce security bands and targets a distinct risk domain within the AI lifecycle.

Band AModel Security

Model Supply Chain

Govern every model from ingestion through to registration. AIBOM generation, CVE scanning, Cosign signing and an OPA gate ensure only clean, verified models reach production.

AIBOM generation & attestation
CVE scanning (ModelScan)
Cryptographic signing (Cosign)
OPA promotion gate
Trusted model registry
Explore Band A →
Band BData Security

Data Ingestion Security

Secure every document, embedding and data asset before it reaches your vector database. Malware and PII checks gate every ingest event; signed provenance is maintained throughout.

Malware scanning (ClamAV)
PII detection & field-level redaction
Data asset signing
Milvus vector DB security gate
Signed embedding provenance
Explore Band B →
Band CAI Guardrails

Prompts, APIs & Agents

Enforce responsible AI policy at the prompt, API and runtime layer. NeMo Guardrails, OPA and Garak work together to block injection, jailbreak, and tool abuse before they land.

NeMo Guardrails
OPA policy engine
Prompt injection detection
Jailbreak & persona prevention
Agent tool allow-list
Explore Band C →
Band CRed Teaming

Adversarial AI Testing

Continuous synthetic red teaming using Garak across all AI surfaces. Every probe run updates a live findings dashboard with severity classification, ready for your SOC queue.

Garak automated probes
Prompt injection coverage
Jailbreak & encoding attacks
Agent tool abuse scenarios
Severity-classified findings dashboard
Explore Red Teaming →
Band DSecurity Telemetry

Audit, Drift & SIEM

Every policy decision becomes a security event. Immutable audit log, model drift monitoring, and SIEM-ready export give SOC teams real-time AI security visibility.

Immutable audit log
Model drift (Evidently AI)
SIEM export (Splunk, Sentinel, QRadar, ELK)
CEF / LEEF format support
Compliance scorecard
Explore Band D →
PlatformAgentic AI Controls

Agentic System Security

Multi-step AI agents introduce compound risk — tool abuse, privilege escalation, and cross-session persistence. Recce applies per-session scope enforcement and full call tracing.

Per-session tool allow-list (OPA)
Privilege escalation prevention
Cross-turn persistence detection
Agent call tracing
Agentic audit trail
View Platform →
Platform · Live Interface

The platform in action.

Every security event, policy decision and drift signal in a single pane — from model supply chain through to runtime telemetry.

Band A · Model Supply Chain
Recce Supply Chain dashboard showing model scan status, AIBOM generation and OPA gate decisions
Supply Chain Dashboard
Model table · AIBOM · CVE scan · Deployment state
Band A · Model Registry
Recce Model Registry showing registered models with attestation and provenance status
Model Registry
Registered models · Cosign attestation · Promotion history
Band C · AI Guardrails
Recce Guardrails policy evaluation log showing DENY and ALLOW decisions across RAG and prompt injection probes
Policy Evaluation Log
41 evaluations · 23 denials · RAG gate · Prompt injection
Band D · Security Telemetry
Recce Telemetry dashboard showing tool-call trace log and Evidently AI model drift monitor panels
Telemetry & Drift Monitor
Tool-call trace · Data drift · Concept drift · Evidently AI
Get Started

Which AI surface do you need to secure first?

Start with a technical review. We'll map your AI stack to the relevant Recce controls and identify the fastest path to coverage.