NEWS
Portal26 Recon Turns Stored Prompts Into Live Answers
Portal26 Recon lets security teams ask GDPR, CCPA and ISO 42001 questions against stored prompts, because quarterly AI reviews already lost the race.
Portal26 Recon is live as a plain-language query layer that lets security and compliance teams ask how AI is used across the company. It reads prompts, responses, agents and tools, then returns evidence on risk, governance and usage, and it is available now to enterprise customers.
Chief executive Arti Raman said AI leaders are accountable for how the business uses the tools, yet they still cannot answer the nuanced questions thrown at them. Recon is the company’s attempt to make those answers searchable against data it already stores.
Portal26 Recon Answers the Questions Dashboards Miss
Portal26 bills the feature as a way to “talk to your AI data.” Teams type ordinary questions instead of building another dashboard filter, and the system answers from consumption records plus company, user, intent and behavior context.
That is a different job from a weekly SOC review. Agentic systems change their own tool calls between meetings, and a static report is stale before it is circulated. The product is built to keep asking the live pile of prompts rather than wait for the next scheduled audit.
The company says Recon can also draft risk scorecards and fix plans, then flag new gaps when rules change. For a SOC, that means hunting detection holes and adjusting posture in a loop, rather than a quarterly spreadsheet pass.
QUESTIONS RECON IS BUILT TO ANSWER
- Privacy law: How current AI use maps onto GDPR or CCPA duties, with the stored prompts as evidence.
- AI management: Where activity sits against ISO 42001 requirements, and which controls are missing.
- Detection gaps: Which agents and tools the SOC is not seeing, and what a posture change should cover next.
- Audit packs: Scorecards, fix plans and exportable records when legal or compliance asks for proof.
Those answers only exist if the underlying traffic was captured. Portal26 has been selling a NIST-certified AI transaction vault that logs each interaction as an immutable record, and Recon sits on top of that store rather than replacing it.
The Prompt Vault That Makes Recon Possible
The query box is new. The archive is not. Portal26 said in 2025 that a NIST FIPS certified GenAI forensic vault had been part of the original platform since 2023, built for prompt discovery, regulatory reporting, insider-risk work and legal holds.
The company, which previously operated as Titaniam, presents itself as a GenAI adoption-management platform rather than a single sensor. Raman’s public case is blunt: if you cannot see what is happening inside GenAI tools, you cannot govern it, and if you cannot govern it, you cannot defend it.
Portal26 has also told customers that a 2024 U.S. federal case, Tremblay v. OpenAI, treated prompts and outputs as subject to discovery. That claim is the company’s reading of the case, and it is why a searchable vault is the real product underneath the new chat window.
Customer-Held Keys on the Forensic Vault
The vault is marketed as the only NIST FIPS certified store for complete GenAI transactions, with analytics that run while prompts stay encrypted. Customers can hold their own keys and shut the vault off, which is the control regulated buyers ask for before they will retain the traffic at all.
FIPS is not a vague badge. The underlying FIPS 140-2 cryptographic module requirements are the U.S. standard for how a crypto module must be built and tested. Without that store, a natural-language layer would have nothing trustworthy to quote in an audit.
A $9 Million Round and Seven-Figure Contracts
On November 4, 2025, the Los Gatos, California company announced a $9 million Series A in November led by Shasta Ventures, with Fusion Fund and the venture arm of a Fortune 500 financial firm. It had raised a $6 million seed round in 2022, bringing total capital to $15 million.
Raman said a vast majority of customers have made large multi-year commitments of up to 7 figures. Lu Zhang, founder and managing partner of Fusion Fund, said at the raise that the platform already monitored hundreds of thousands of enterprise GenAI users.
HOW PORTAL26 GOT TO A QUERY LAYER
- 2022: Raises a $6 million seed round.
- 2023: Ships the NIST FIPS certified GenAI forensic vault as part of the original platform.
- November 4, 2025: Closes a $9 million Series A led by Shasta Ventures.
- March 19, 2026: Launches an Agent Management Platform to discover agents and trace their calls.
- June 2, 2026: Offers free governance and security for enterprise Claude deployments.
- September 2026: Releases Recon as a plain-language query layer on that stored AI data.
By September 9, 2026, product notes were already describing Recon as a way to interrogate governance, performance and cost in ordinary English. Cost belongs in that list because agent loops burn tokens whether or not a CISO is in the thread, and finance will ask the same box the SOC uses.
IBM Put a $670,000 Price on Ungoverned AI
The reason a live question layer exists is that most companies still cannot say what their AI is doing. IBM and the Ponemon Institute studied 600 breached organizations from March 2024 through February 2025 for the 2025 Cost of a Data Breach Report, the first edition to treat AI security, governance and shadow AI as first-class subjects.
The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it. The report revealed a lack of basic access controls for AI systems, leaving highly sensitive data exposed, and models vulnerable to manipulation.
Suja Viswesan, Vice President, Security and Runtime Products, IBM
IBM’S 2025 AI OVERSIGHT GAP
| Metric | Figure | Scope |
|---|---|---|
| AI model or application breaches | 13% | of 600 studied organizations |
| Unknown whether AI was compromised | 8% | of 600 studied organizations |
| No proper AI access controls | 97% | of organizations that reported an AI-related breach |
| No AI governance policy, or still writing one | 63% | of breached organizations |
| Regular audits for unsanctioned AI | 34% | of organizations that already have an AI governance policy |
| Breach tied to shadow AI | 1 in 5 | of studied organizations |
| Policies to manage AI or detect shadow AI | 37% | of studied organizations |
| Extra cost with high shadow AI | $670,000 | versus organizations with low or no shadow AI |
Among the AI-related incidents, 60% led to compromised data and 31% led to operational disruption. Shadow AI incidents also hit personal data in 65% of cases, against a 53% global average, and intellectual property in 40%, against 33%.
The expensive part is the delay. If only 34% of companies that already wrote an AI policy then audit unsanctioned tools, a quarterly review is the control most boards still think they have. Recon is a bet that the next question will arrive by email from counsel, not on the SOC calendar.
What CISOs Can Ask About GDPR and ISO 42001
The sample questions Portal26 uses are not SOC trivia. They are the ones a board, a regulator or a customer contract will ask: does this usage break GDPR or CCPA, and does the program hold up against ISO/IEC 42001 AI management standard requirements.
ISO/IEC 42001:2023 is the first international standard for an AI management system. It tells an organization how to set policy, assign roles, run risk treatment, govern data, watch the system through its life, and improve. It applies to firms that build AI, buy it, or run someone else’s model.
Every AI leader I talk to is wrestling with the same problem: they’re accountable for how AI is used across the business, but they don’t have a way to answer all the nuanced questions thrown at them.
Arti Raman, CEO, Portal26
A query that returns “here are the prompts that look like personal data leaving for a public model” is closer to what an auditor wants than a slide that says AI is in use. Compliance and legal teams are a named audience for that reason: they need evidence as rules shift, not another heat map.
ISO 42001 still asks for leadership, documented policy, and continual improvement. A chat window does not write the policy. It can show whether the policy matches the traffic, which is the part most programs never get to.
Forward-Deployed Engineers and the Post-Launch Blind Spot
Portal26 also aims Recon at forward-deployed engineers, the people who ship AI apps and agents into production and then lose sight of them. The pitch is visibility before, during and after deployment, which is a polite way to say most teams still treat launch day as the end of the story.
That gap grew as the company moved from chat tools into agents. In March 2026 it launched an Agent Management Platform that discovers agents on laptops, in hyperscale estates and inside SaaS, then shows the model, the users, the call volume and the prompts passing between agent and model.
On June 2, 2026, Pakshi Rajan, chief GenAI and product officer, put the same problem in Claude-specific terms. “Deploying Claude is the starting point. What organizations need upfront is the infrastructure to discover all Claude AI, Claude Code, and Claude Cowork usage, surface all conversations and tool calls, govern it, protect it, and prove its value,” Rajan said.
Engineers will use Recon as a production trace, not a policy essay. CISOs will use it when the board asks which unsanctioned agents exist. Legal will use it when a discovery request names prompts. One query box serving those three jobs is the design, and it only works if the vault was on before the agent shipped.
Missing Prompts Stay Missing After the Query
Recon does not invent a history that was never logged. Companies that blocked ChatGPT on the proxy but never captured prompts still cannot prove what left through personal accounts, browser extensions or embedded SaaS agents.
It also does not certify anyone against ISO 42001, and it does not make a GDPR file complete. Those are management-system and legal jobs. The software can assemble evidence and a fix list; a certification body and counsel still have to stand behind the result.
WHAT RECON DOES NOT PROVE
- Unlogged traffic: Prompts that never hit the vault cannot be queried, scored or produced in discovery.
- Legal sign-off: A GDPR or CCPA answer from the tool is evidence for counsel, not a filing.
- ISO certificates: Mapping activity to 42001 controls is not the same as an accredited audit.
- Public access: The feature is for Portal26 enterprise customers, not a free lookup anyone can run.
The honest limit is also the product’s point. Periodic reviews failed because the traffic moved faster than the calendar, and because most firms never stored the prompts in a form they could search. Recon is available to those enterprise customers now, and it will answer the next GDPR or ISO question only for traffic the vault already kept.
Frequently Asked Questions
Does ISO/IEC 42001 replace GDPR or other AI laws?
No. ISO says the standard does not replace laws or regulations. It is a management framework that can help a company meet duties it already has. Certification is voluntary, ISO itself does not certify anyone, and independent certification bodies do that work.
What does FIPS 140-2 actually test in a prompt vault?
FIPS 140-2, published May 25, 2001, sets security requirements for cryptographic modules across 11 areas, including key management, physical security and self-tests, with four rising security levels. A vault that cites it is claiming a tested crypto module, not a general “encryption” slogan.
How was IBM’s 2025 shadow AI research done?
Ponemon Institute conducted the study and IBM sponsored and analyzed it, using data breaches at 600 organizations globally from March 2024 through February 2025. The Cost of a Data Breach series is in its 20th year and has investigated nearly 6,500 breaches; 2025 was the first year it treated AI governance and shadow AI as core topics. The global average cost of a data breach in that edition was $4.44 million.
What is an AI management system under ISO 42001?
ISO describes it as a structured set of policies, processes and controls for how AI systems are designed, developed, deployed and used. In practice that means defined responsibilities, data-quality and performance checks, handling of legal and ethical issues, and monitoring through the system’s life, not a one-time model review.
-
NEWS1 month agoMeta’s Smart Glasses Sell a Light That Needed Two Patches
-
NEWS1 month agoSong Yadong Stops Umar Nurmagomedov the Only Way Left
-
NEWS1 month agoGoogle’s Free AI Pro Year Is Three Different Deals
-
NEWS1 month agoApple’s New Mac Studio Clusters Local AI on the Desk
-
NEWS2 months agoThe Mahape Fake Apple Raid Repeats a Dual-Shift Pattern
-
ENTERTAINMENT2 months agoGomez Says She Never Ran the Wondermind Investors Backed
-
ENTERTAINMENT2 months agoLUN8’s First London Concert Filled a 620-Cap Club
-
ENTERTAINMENT1 month agoLanterns Puts Sinestro in a Cell and Lets Him Talk
