Confidential technical resources for evaluating First Recon AI. Access is provided by your First Recon contact.
How the runtime evaluates meaning, intent, sensitive data, and threats using the identity, device, destination, policy, and history relevant to the interaction.
One decision is several scans. Inside the Semantic Security Engine™, mixture-of-experts routing reads what an interaction carries and dispatches the specialists built for it: threat models and classification models scan in parallel, reasoning agents weigh every detection against the actor, the destination, and the request itself, and mixture-of-agents composition turns their findings into one reading. Deterministic policy makes the final call, and designated reviewers decide the holds. No single agent is trusted alone with the call, so a miss by one scanner is not a miss by the engine.
The release uses a dual-key system, which prevents any interaction from clearing on a single scan. Two composed scans from independent model lineages must agree before the interaction is released. The second key is self-hosted on infrastructure controlled by First Recon AI.
A false negative would need to pass through two systems with different designs. If either required scan goes silent, the interaction is held and the decision path fails closed.
The bench is benchmarked continuously and evolves as stronger threat and classification models arrive; accumulated detection context carries forward through the change, so detection improves without resetting.
The Security Context Graph™ supplies the identity, device, data classification, destination, applicable policy, and relevant prior decisions for each interaction. Semantic Security uses that context to determine the appropriate control. If an interaction is held for human review, designated reviewers can inspect it until they decide.
Workspace content follows your tenant's configured retention settings. The evidence ledger separately records decision metadata and does not create another copy of prompt or response bodies.
The security models that scan traffic are First Recon models hosted in-house on infrastructure First Recon controls. Customer prompts are not sent to an outside AI model provider for security analysis.
Today the engine's models execute on infrastructure First Recon controls, and your prompts are not sent to a third party to be scanned. Consolidation onto a dedicated GPU fleet First Recon operates in AWS accounts it controls is in build: live end-to-end in development, not yet cut over in production. Cutover changes which First Recon-controlled infrastructure the models run on, not the third-party boundary.
A class your administrators designate always-block is blocked regardless of context. Hard rules are never overridden: semantic judgment adds nuance on top of deterministic rules, never under them.
When meaning or intent is genuinely unclear, the interaction holds for human review rather than being guessed either way.
The engine evaluates each interaction and produces a decision at the point of enforcement, before the interaction proceeds. It operates in the enforcement path instead of reviewing copied traffic from a sidecar. The security architecture also defines how the system responds when the runtime cannot complete an evaluation.