Recon Studio
Choose an objective — Recon assembles the proof path from intent to audit-ready evidence. Observe-first; model boundaries before enforce.
Observe-only by default — no autonomous execution in phase 1. SIEM export uses observeOnly: true; bounded authority defaults to enforcementActive: false.
Where should I start?
Choose an objective — Recon assembles the proof path from intent to audit-ready evidence.
What outcome will I get?
Recommended loop for your objective — flagship paths show truthful maturity labels, not route availability.
- 1Complete loop7/7Intent Assurance WorkspaceImplementation Assurance Blueprint and compiler confidence scores
- 2Audit-ready4/7Mission ControlMission lifecycle state and verification summary
- 3Runtime-connected2/2 required stagesTrust AlignmentRuntime alignment report and drift signals
- 4Evidence-only1/1 required stagesAudit PacketAuditPacketV1 bundle for GRC reviewers
What happens next?
Supporting proof artifacts and platform tools — compose into your loop, not equal starting points.
AI Receipts™
GhostLog-backed trust receipts for agent steps — portable proof for any AI system.
Trust Statements™
Operator-readable trust posture statements derived from receipts and governance context.
Trust Replay™
Timeline replay of trust events — reconstruct what happened before escalation.
Trust Evidence Packet Generator™
Package governance, runtime, lineage, containment, and reconstruction evidence into a review-ready artifact.
TrustGraph
Lineage graph for trust events, missions, and verifier continuity.
Trust Accounting
The ledger system for AI decisions — receipts, movements, timelines, and diagnostics.
Exposure Guard
Portfolio exposure posture for agentic workflows — containment previews and risk bands.
Governance Studio
Governance artifact workspace for policy families, approvals, and runtime bindings.
Trust Signal Surface
Live trust signal discovery engine for operator dashboards.
Social Reflex
Engagement reflex surface for trust-aware social workflows — advisory preview.
Agent Credit Score™
Trust Score API — add trust scores to any AI system with diagnostics.
Compare Frameworks
Intent Evolution Engine — diff two governance artifacts across intent, runtime projection, and trust impact.
Compiler Performance
CVM-1 benchmark rollup — Intent Fidelity, coverage, projection accuracy, and Trust Lock health.
TrustOps Control Plane™
Continuous TrustOps operating surface — identity, authority lineage, governance contracts, and drift signals.
Define → validate → preview → evidence → SIEM → verify
The evaluator spine for security sponsors: declare boundaries, emit portable proof, forward to your SOC, then verify with replay and audit packets—observe-first throughout phase 1.
- 1Define
Governance contract & policy intent (preview)
- 2Validate
Schema + doctrine checks
- 3Preview risk
Synthetic GhostLog posture — not live enforce
- 4Evidence
GhostLog, portable bundles, org export
- 5SIEM
NDJSON/CEF forward with observeOnly
- 6Verify
Timeline replay & evaluator packet
Builder tooling (loop completion, promotion receipts)▾
Loop Completion Dashboard
Builder-only maturity ledger — derived stage counts, missing loop gaps, and flagship promotion receipts. Public surfaces cap promotion-gated products until receipts pass.
Open loop completion dashboard →Operator tooling (PoV, Trust Loop, SIEM compose)▾
Run Enterprise PoV
pnpm demo:enterprise-pov from repo root (~20–30 min).
pnpm demo:enterprise-povEnterprise Trust Loop
Deep evaluator walkthrough (~45–90 min) with dashboard checkpoints.
scripts/enterprise-trust-loop-v1.shGenerate AuditPacket
Portable evaluator handoff for security, GRC, and audit reviewers.
pnpm audit-packet:generateSIEM docker eval
Compose stack + sample NDJSON—verify HMAC and observeOnly posture.
deploy/docker-composeTimeline replay
Dashboard preview at /policies/timeline-replay—sign in for workspace scope.
Governance previews
Contracts, authority lineage, and containment—preview badges only.
Preview vs enforced
Use in security questionnaires and procurement—honest about what runs at runtime today.
| Surface | User-visible behavior | Enforced at runtime? |
|---|---|---|
| TrustGovernanceContractV1 | Badges, synthetic GhostLog preview JSON | No — not wired to guard.ts |
| Authority / lineage preview | Trust badges, synthetic events | No |
| Containment / sandbox preview | Risk score, boundary badges | No — metadata only, not VM isolation |
| SIEM export | Forward rows to webhook/SIEM | No new blocks — observe-only forwarding |
| Guard ingest (integrated paths) | Block/allow on configured ingest | Yes — where integrated |
| Trust Lock runtime_strict | Tool call signature on governed swarm path | Yes — scoped path |
| Bounded authority bindings | Audit + activation records | Mostly audit — default enforcementActive: false |
What Recon.AI is
- •AI runtime governance and trust evidence for regulated copilots and agentic workflows.
- •Connects Reflex, guard ingest, and GhostLog to declared governance boundaries and exportable survivability evidence.
- •Leads observe-first: prove what happened in your existing SOC before graduating enforcement on scoped paths.
What Recon.AI is not
- •Not a replacement SIEM (Splunk, Sentinel, Datadog)—forwards trust-shaped telemetry into them.
- •Not HIPAA/SOX/certification—evidence infrastructure and declarative samples only.
- •Not compute sandbox isolation—containment v1 is metadata and preview badges.
- •Not crypto-signed non-repudiation in v0—attestations are hash-only by design.
Recon leads with observation, declared boundaries, and exportable evidence. Enforcement on integrated paths and Trust Lock requires explicit configuration—bounded authority activation defaults off (enforcementActive: false). Illustrative JSON keeps carriesExecutionAuthority: false.
Ready for a scoped pilot?
14-day enterprise pilot or 30-day Founding Cohort activation—both lead with observe-only SIEM eval and portable evidence.