Confidential technical resources for evaluating First Recon AI. Access is provided by your First Recon contact.
Enforcement at the endpoint over the AI in use on macOS and Windows devices, including AI tools you do not own or host: the coverage model, what it observes and enforces, how it deploys through your MDM, and the privacy stance toward your own people.
Policy is written against named AI services, driven by one catalog of AI destinations, curated entries plus the ones you add. Each destination carries a category and a confidence score, and AI embedded inside SaaS applications is flagged as such.
| Where AI shows up | How it is recognized | What a rule looks like |
|---|---|---|
| Browser AIchat sites, personal AI accounts | Named service resolved from the connection, with the browser as the opening application | Block personal AI accounts for the whole fleet; warn on unclassified destinations |
| Desktop AI appsinstalled assistants | Application identity with its code signer, plus the destination it talks to | Sanction a named desktop assistant for one department |
| Code and IDE assistantsdeveloper tooling | Named service per assistant; the IDE or CLI is the opening application | Allow a named coding assistant for Engineering: a single rule |
| AI inside SaaSembedded copilots | Flagged as embedded AI on the parent service, with its own category and confidence | Monitor first, then decide per service and team |
Coverage travels with the device, on or off the corporate network, because the decision point is the device itself rather than a network chokepoint.
A fleet-wide inventory of AI in use: who or what is acting, what data, which tool. The telemetry contract admits AI events only. The agent observes AI use, not people, and logs decisions, not content.
Allow, redact, warn, block, or hold for human review, decided and enforced at the endpoint before the prompt reaches the model's API. Allowed traffic goes straight to the model; no proxy in the path.
| Control | What it does |
|---|---|
| Allowlist | Sanction a named AI service for one department or the whole fleet |
| Block | Drop the connection at the endpoint, before data reaches a model; scope it to one named service, a provider, or all unsanctioned AI |
| Warn | Let the flow proceed with a recorded warning decision; user overrides become part of the evidence trail |
| Monitor | Log-only visibility with no user impact; new deployments start here |
| Default | When no rule matches, the tenant default decides; the failure posture is yours to set, fail-open or fail-closed |
| Receipts | Every decision is written as a signed receipt naming the outcome, the deciding rule or default, and the policy revision it ran under |
Detection is semantic, drawing on the Security Context Graph™, so a customer identifier that means nothing outside your organization is still recognized inside it; the depth is on Semantic security.
The rollout is the motion your endpoint team already runs for any agent: package, target by group, manage policy centrally. No new infrastructure, no network changes.
Deploys through the MDM your fleet already runs, Jamf, Intune, and others, targeted by the device groups you already maintain.
Built to run beside your EDR and device management agents. Before rollout, our engineers walk your endpoint team through the interception path, the resource envelope, and coexistence with what you already run.
Device enrollment is admin-controlled, and device credentials rotate and revoke on demand, so a lost or retired device stops being a policy question immediately.
Pilot device group first, monitor-mode visibility from the first check-in, then per-rule enforcement as your team decides. The full journey is on Deployment.
An endpoint security lives or dies on what it refuses to collect. The contract is narrow on purpose.
| Audience | What they see | What they never get |
|---|---|---|
| The person using the device | Warnings and blocks are visible in the moment, with the policy reason; overrides they choose are recorded | Silent surveillance of non-AI activity; the agent is not a general activity monitor |
| Your IT and security team | The AI inventory: named service, opening application and code signer, device, acting user, category and confidence, decisions | Keystrokes, screen contents, or browsing outside AI flows; the telemetry contract admits AI events only |
| What leaves the device | The decision and its sealed, metadata-only receipt, streamed to your SIEM | Raw prompts and data are not retained as evidence; a held item stays visible to designated reviewers until they decide, then the trail keeps the decision, not the content |
| Platform | Status | Management |
|---|---|---|
| macOS | Supported | Enrolled and managed through your MDM |
| Windows | Supported | Enrolled and managed through your MDM |
The Endpoint Security is a macOS and Windows product today; mobile devices are not an Endpoint Security surface.