Your PM needs to check if users are active. That requires SQL. Your support lead needs to understand how a feature works. That requires GitHub. Your ops person needs ticket status cross-referenced with customer data. That requires Linear + database access.
Every time, they message an engineer. The engineer context-switches, runs a query, pastes a result, and loses 30 minutes of deep work. Multiply that across your team, every day.
Recon connects to your database, codebase, Linear, and Notion. Your non-technical team asks a question in plain English and gets a full investigation - real SQL queries, real code navigation, real ticket lookups - with every source cited.
No MCP setup. No CLI tools. No prompt engineering. Just a chat interface that actually works for people who aren't engineers.
What's under the hood:
Optimized tools running in a secure sandbox (not raw API dumps)
Real SQL execution against your production database
Repo cloned at startup — agent navigates code like an engineer would
Structured Notion and Linear search with clean, parsed responses
File generation and export inside the same conversation
Try it free: 50 queries, 3 connections, no credit card. Paid plans start at $19/mo with BYOK (bring your own API key) so you control your AI costs.
Strong value prop. Reducing engineer interruptions is a real productivity win.
Since Recon connects to production systems, security boundaries will define trust:
• When you say “real SQL execution against your production database,” how are you preventing destructive queries or privilege escalation? Is access read-only by default?
• Are database credentials stored encrypted and scoped per workspace?
• If you support BYOK, are prompts or query results ever retained on your side?
This touches live production data, internal tickets, and proprietary code. Strong sandboxing, least-privilege access, and strict tenant isolation will be critical for enterprise adoption.
Concept is sharp. If you make the security model explicit and boring, teams will feel safe letting non-engineers use it.
Really appreciate this, these are exactly the right questions. Here's where Recon stands:
All database access is read-only by default. Queries run in sandboxed E2B environments that are destroyed after each investigation. No persistent connections to production.
Credentials are encrypted and scoped per workspace. Team members never see the actual keys, they just get access to query.
With BYOK, prompts go directly to the model provider. Recon stores conversation history and tool results so teams can reference past investigations. Database credentials are encrypted and never exposed to end users.
Each workspace is fully isolated. No cross-tenant data access.
Your point about making the security model "explicit and boring" is spot on. I'm adding a dedicated security page to make all of this visible upfront. Appreciate the detailed feedback.
Appreciate the detailed breakdown. Read only by default and short lived sandbox environments are the right starting point.
A few areas to keep tightening as adoption grows:
• Enforce read only at the database role level, not only in application logic
• Restrict queries to predefined schemas where possible
• Log and alert on unusual query volume or access patterns
• Define clear retention limits for stored investigation history
Encrypted, workspace scoped credentials and no key exposure to end users are strong controls. Make the key management and rotation policy explicit as well.
For BYOK, clarity matters. If prompts go directly to the provider but conversation history is retained, document:
• What is stored
• For how long
• How it is isolated per tenant
• How customers can delete it
When a tool touches production databases and internal tickets, least privilege and auditability are non negotiable.
Publishing a clear, simple security page will reduce friction with technical buyers.
As a security team building Nautillo Pro, we follow the same principles. Strict scope. Strong isolation. Continuous external validation of exposed paths.
If you ever want to test your own production surface from an external attacker perspective, Nautillo Pro has a free version available.