Confidential technical resources for evaluating First Recon AI. Access is provided by your First Recon contact.
How sensitive data is protected on the governed path. Interactions are judged by meaning and intent, not pattern matching alone, and enforced inline before a model is reached, with policy coverage from day one and data that stays yours.
Enforcement runs in both directions. Prompts are judged on the way in, model responses on the way out, held to the same policy. Hard rules are never overridden; semantic judgment adds nuance on top of them. How the decision is made is on Semantic security.
| Decision | What happens to the interaction | What the evidence shows |
|---|---|---|
| Allow | Proceeds untouched to the model | Sealed receipt naming decision, policy + version, actor, and surface |
| Redact | Sensitive spans redacted in place; the rest proceeds; work keeps moving | Receipt + the classes redacted (never the content) |
| Hold | Pauses for a designated reviewer; releases or blocks on their call | Receipt + reviewer decision; the trail keeps the decision, not the content |
| Block | Never reaches the model; the user sees the policy reason | Receipt naming the rule that fired |
Where in the flow the decision lands.
You're covered with 300+ out-of-the-box policies covering your industry, sector, geography, and compliance frameworks. Detection templates identify sensitive data, industry presets select the relevant coverage, and policy templates provide rules your team can review and deploy.
No policies match your search.
Verified against the product catalogs on July 20, 2026, spanning 18 out-of-the-box detection templates with 233 detection patterns, 22 industry presets, and 300+ policy templates. Each entry expands into what it covers; detection templates also list their individual pattern names, verified against the product catalog.
The catalogs are the starting point, not the boundary. Administrators create custom policies in the product's policy builder (name it, scope what it covers, define its rules) and deploy them through the same enforcement path. A policy written for your organization behaves exactly like one that shipped in the box.
Prompts, responses, files, and company knowledge may be stored in your tenant under its configured retention settings so authorized users can return to their work and history.
The evidence ledger separately records the policy, actor, destination, classification, and outcome. It does not create a second copy of prompt or response bodies.
First Recon does not use customer prompts, responses, files, or company knowledge to train its models.