Confidential technical resources for evaluating First Recon AI. Access is provided by your First Recon contact.
Yes, when the work crosses the Secure Enterprise AI Workspace, Endpoint Security, or the gateway. Endpoint Security can identify agent and AI-tool usage on a managed device and apply allow, block, or redirect policy at the endpoint boundary. Agent traffic routed through the workspace or gateway receives full runtime policy and approval gates. First Recon cannot control activity inside a third-party tool unless that vendor exposes, and the customer configures, a compatible integration. The full map is in the Solutions Guide brief.
Endpoint Security can discover SaaS and AI access on managed devices and allow, block, or redirect it before the application opens. It cannot govern actions inside a third-party SaaS interface unless that vendor exposes, and the customer configures, a compatible integration or API. That is a structural limit of endpoint controls, not a First Recon-specific limitation. Work performed in the Secure Enterprise AI Workspace receives full inline policy enforcement. The full map is in the Solutions Guide brief.
Agents are governed like human users: the same access policies and logging apply, with policy enforced at the action, including approval gates, rather than only at login or agent creation.
Policy applies across users and agents with tenant isolation, and tool connections carry scoped permissions so a given connection only grants what it was configured to grant.
Runtime detection screens every interaction; per-identity decision records export to your SIEM, where behavioral anomaly analytics run on evidence we supply.
Hard budgets and caps by department, user, and project; real-time usage visibility; and runaway-agent spend prevention. Smart Select routes to an appropriate model, and caching reduces spend.
In chat, Smart Select automatically routes each message to the best model within the pool your governance policy allows, with cost-savings reporting for administrators. Routing by sensitivity or latency is not offered today.
Yes: multi-tenant SaaS is the standard deployment, and the architectures from single-tenant up to on-premise are described in Hosting options. Heavier options are scoped as an engagement with your account team rather than self-serve.
Not in the standard multi-tenant deployment: no private-model or local-LLM routing exists in the platform today. If this is a requirement for your evaluation, raise it with your account team; requirements like this are scoped directly with customers.
Hybrid deployment, where First Recon operates the control plane and your data plane stays under your control, is one of the architectures on Hosting options, scoped directly with your account team. Public-plus-local model routing is a separate question: no local or private LLM routing exists in the platform today.
The runtime logs decisions, not content, and evidence exports to your SIEM; the full story is under SIEM on Integrations and the Trace function on Security architecture. A governance and audit report surfaces DLP events, detections, and policy actions. Evidence retention follows your deployment option and policy.
Usage analytics are available by user, department, and project.
No questions match your filter.
Pricing, a tailored deployment plan, security documentation under NDA, or a live technical walkthrough: your First Recon team picks up where these pages stop.
Contact Sales