Security · GRC · Platform · EA
View full TrustOps lifecycle →

Recon Studio

Choose an objective — Recon assembles the proof path from intent to audit-ready evidence. Observe-first; model boundaries before enforce.

Observe-only by default — no autonomous execution in phase 1. SIEM export uses observeOnly: true; bounded authority defaults to enforcementActive: false.

Where should I start?

Choose an objective — Recon assembles the proof path from intent to audit-ready evidence.

What happens next?

Supporting proof artifacts and platform tools — compose into your loop, not equal starting points.

Evidence-only2/3 required stagesproof

AI Receipts™

GhostLog-backed trust receipts for agent steps — portable proof for any AI system.

Evidence-only1/2 required stagesproof

Trust Statements™

Operator-readable trust posture statements derived from receipts and governance context.

Evidence-only2/3 required stagesproof

Trust Replay™

Timeline replay of trust events — reconstruct what happened before escalation.

Evidence-only1/1 required stagesproof

Trust Evidence Packet Generator™

Package governance, runtime, lineage, containment, and reconstruction evidence into a review-ready artifact.

Runtime-connected2/2 required stagesplatform

TrustGraph

Lineage graph for trust events, missions, and verifier continuity.

Platform1/2 required stagesplatform

Trust Accounting

The ledger system for AI decisions — receipts, movements, timelines, and diagnostics.

Platform2/7platform

Exposure Guard

Portfolio exposure posture for agentic workflows — containment previews and risk bands.

Platform2/2 required stagesplatform

Governance Studio

Governance artifact workspace for policy families, approvals, and runtime bindings.

Runtime-connected1/1 required stagesplatform

Trust Signal Surface

Live trust signal discovery engine for operator dashboards.

Advisory0/0 required stagesintelligence

Social Reflex

Engagement reflex surface for trust-aware social workflows — advisory preview.

Advisory1/1 required stagesintelligence

Agent Credit Score™

Trust Score API — add trust scores to any AI system with diagnostics.

Evidence-only2/2 required stagesworkflow

Compare Frameworks

Intent Evolution Engine — diff two governance artifacts across intent, runtime projection, and trust impact.

Evidence-only2/2 required stagesworkflow

Compiler Performance

CVM-1 benchmark rollup — Intent Fidelity, coverage, projection accuracy, and Trust Lock health.

Runtime-connected3/3 required stagesplatform

TrustOps Control Plane™

Continuous TrustOps operating surface — identity, authority lineage, governance contracts, and drift signals.

Enterprise trust loop

Define → validate → preview → evidence → SIEM → verify

The evaluator spine for security sponsors: declare boundaries, emit portable proof, forward to your SOC, then verify with replay and audit packets—observe-first throughout phase 1.

  1. 1Define

    Governance contract & policy intent (preview)

  2. 2Validate

    Schema + doctrine checks

  3. 3Preview risk

    Synthetic GhostLog posture — not live enforce

  4. 4Evidence

    GhostLog, portable bundles, org export

  5. 5SIEM

    NDJSON/CEF forward with observeOnly

  6. 6Verify

    Timeline replay & evaluator packet

Builder tooling (loop completion, promotion receipts)

Loop Completion Dashboard

Builder-only maturity ledger — derived stage counts, missing loop gaps, and flagship promotion receipts. Public surfaces cap promotion-gated products until receipts pass.

Open loop completion dashboard →
Operator tooling (PoV, Trust Loop, SIEM compose)

Run Enterprise PoV

pnpm demo:enterprise-pov from repo root (~20–30 min).

pnpm demo:enterprise-pov

Enterprise Trust Loop

Deep evaluator walkthrough (~45–90 min) with dashboard checkpoints.

scripts/enterprise-trust-loop-v1.sh

Generate AuditPacket

Portable evaluator handoff for security, GRC, and audit reviewers.

pnpm audit-packet:generate

SIEM docker eval

Compose stack + sample NDJSON—verify HMAC and observeOnly posture.

deploy/docker-compose

Timeline replay

Dashboard preview at /policies/timeline-replay—sign in for workspace scope.

Governance previews

Contracts, authority lineage, and containment—preview badges only.

Preview vs enforced

Use in security questionnaires and procurement—honest about what runs at runtime today.

SurfaceUser-visible behaviorEnforced at runtime?
TrustGovernanceContractV1Badges, synthetic GhostLog preview JSONNo — not wired to guard.ts
Authority / lineage previewTrust badges, synthetic eventsNo
Containment / sandbox previewRisk score, boundary badgesNo — metadata only, not VM isolation
SIEM exportForward rows to webhook/SIEMNo new blocks — observe-only forwarding
Guard ingest (integrated paths)Block/allow on configured ingestYes — where integrated
Trust Lock runtime_strictTool call signature on governed swarm pathYes — scoped path
Bounded authority bindingsAudit + activation recordsMostly audit — default enforcementActive: false

What Recon.AI is

  • AI runtime governance and trust evidence for regulated copilots and agentic workflows.
  • Connects Reflex, guard ingest, and GhostLog to declared governance boundaries and exportable survivability evidence.
  • Leads observe-first: prove what happened in your existing SOC before graduating enforcement on scoped paths.

What Recon.AI is not

  • Not a replacement SIEM (Splunk, Sentinel, Datadog)—forwards trust-shaped telemetry into them.
  • Not HIPAA/SOX/certification—evidence infrastructure and declarative samples only.
  • Not compute sandbox isolation—containment v1 is metadata and preview badges.
  • Not crypto-signed non-repudiation in v0—attestations are hash-only by design.
Observe-first doctrine

Recon leads with observation, declared boundaries, and exportable evidence. Enforcement on integrated paths and Trust Lock requires explicit configuration—bounded authority activation defaults off (enforcementActive: false). Illustrative JSON keeps carriesExecutionAuthority: false.

Ready for a scoped pilot?

14-day enterprise pilot or 30-day Founding Cohort activation—both lead with observe-only SIEM eval and portable evidence.