Confidential technical resources for evaluating First Recon AI. Access is provided by your First Recon contact.
Where data is processed, where it is stored, and who can see it. The hosting architectures that control each, from multi-tenant to on-premise, are on Hosting options.
Residency is two separate questions with different answers, set independently.
Where an interaction is routed and computed while it happens.
Where your knowledge, indexes, and evidence are stored once the interaction is done.
Visibility follows the deployment option. In architectures with customer-held keys, raw customer content stays inside your boundary, and First Recon AI cannot decrypt it. Control-plane providers operate on policy bundles, receipts, license state, and health signals rather than content. The table shows, per data type, where it stays and who can see it.
| Data / control | Where it stays | Who can see it |
|---|---|---|
| Prompts & filesuser content | Your controlled / on-prem data plane | ✓ You. Outside your boundary: no raw prompts, files, or decrypted content; minimized metadata only |
| Security findingsDLP & policy decisions | Your evidence ledger | ✓ You. Outside: decision status, policy IDs, receipt IDs only |
| Audit evidenceapprovals & review trail | Your private audit store | ✓ You. Outside: signed receipt hash and policy version only |
| Logs & telemetryoperations & observability | Your log store | ✓ You. Outside: non-sensitive health counters only |
| Backupsrestore & continuity | Your backup vault | ✓ You. No backup content leaves the boundary |
| Keys & supportaccess control | Your KMS / HSM or customer-approved flow | ✓ You. Outside: support metadata; never keys or decrypted content |
Processing runs at the Cloudflare edge location closest to each user. Model traffic leaves through regional AI gateway lanes. US is the default; EU and UK lanes are built in and activated per deployment. Data-at-rest is the separate axis. Multi-tenant storage is US-resident today; regional instances are provisioned on demand, and single-tenant deployments can pin data-at-rest to an in-country AWS region, an engagement option rather than part of the multi-tenant application today.
| Dimension | In this region |
|---|---|
| Frameworks | SOC 2 Type IIHIPAACCPANIST CSFPCI-DSS |
| Processing | Lands at the Cloudflare edge location closest to each user. Model traffic uses the US gateway lane, the platform default. |
| Data-at-rest | Multi-tenant storage is US-resident today; the default posture matches most North American requirements. A dedicated US-resident instance can be provisioned per engagement, and single-tenant deployments can scope storage to a region in your jurisdiction as part of the engagement. |
| Dimension | In this region |
|---|---|
| Frameworks | GDPRISO 27001PCI-DSS |
| Processing | Lands at the Cloudflare edge location closest to each user. EU and UK gateway lanes are built in for model traffic and activated per deployment. |
| Data-at-rest | Multi-tenant storage is US-resident today. In-region EU storage is available on demand as part of a regional engagement, and single-tenant deployments can pin data-at-rest to an in-country AWS region as part of the engagement. |
For organizations that must keep raw content away from any US-owned provider, Who can see your data above answers the sovereignty question directly. Customer-controlled or on-premise architectures with customer-held keys keep raw content inside your boundary.
| Dimension | In this region |
|---|---|
| Frameworks | APPI jurisdiction controlsISO 27001SOC 2 Type II |
| Processing | Lands at the Cloudflare edge location closest to each user. |
| Data-at-rest | The APAC regional instance is Singapore: in-region for APAC, not in-country for Japan. In-Japan storage is a single-tenant engagement pinned to an in-country AWS region such as AWS Tokyo: an engagement option, not part of the multi-tenant application today. |