The Fail-Safe for Enterprise AI.
Know what went into the AI you ship, control what it does in production, and prove it all. Jozu Hub verifies and secures models, agents and MCP servers. Agent Guard enforces your policy and contains your agents on your own Kubernetes, connected or air-gapped.
From the team behind KitOps, a CNCF project.
Created by the team behind KitOps, a CNCF project.
Runs fully disconnected. Awardable on the CDAO Tradewinds and Platform One Solution Marketplaces. Jozu for defense
Trusted by practitionersWe're building a vendor-agnostic MLOps platform and KitOps ModelKits align perfectly with that vision. They work wherever our containers do — on-prem or in the cloud — giving us the freedom to store and deploy ML artifacts without being tied to a specific infrastructure.
No more gaps, no more patch work.
Before execution
Jozu scans every model, agent, and MCP server, from malicious code execution and backdoored weights to prompt injection and dataset poisoning. The results are signed and attached to the artifact, then artifacts that fail are blocked before they load.
How Jozu verifies AI artifactsDuring execution
Jozu enforces organizational policies wherever AI executes. Block malicious prompts and redact sensitive data when chatting with frontier models. For local agents we isolate them and control what goes in and out, and what tools they use.
How Agent Guard enforces policyAcross them both
Every policy decision, security scan result, human approval, and AI asset change is captured in one tamper-evident, cryptographically chained audit record. It's attached to your AI package's metadata and can be exported with just one-click.
How Jozu Hub keeps the recordKnow what's inside before it runs.
Every model, agent, and MCP server is scanned across nine vulnerability classes, from malicious code execution to prompt injection or data set poisoning. Approved artifacts are signed so they can be verified by every client.
What you haven't approved doesn't run. Unvetted AI is blocked before it is loaded, stopping risky shadow AI.
Nothing gets past your policy.
Jozu Agent Guard evaluates every agent action against policy at the moment it happens, locally without any network dependency. Denied actions get a reason, an audit entry, and a compliant path forward.
Gain visibility into AI across your organization
Jozu lets you curate an approved catalog of models, agents, skills, and MCPs that are vetted and trusted. It keeps an immutable, tamper-evident log of all of it, so you can see the whole picture.
Jozu's audit log is cryptographically chained and can be used for regulatory compliance evidence.
How Jozu fits your stack
Jozu uses the same open source container standard you already use with Docker and Kubernetes. There's no vendor lock-in, or proprietary formats. Best of all, Jozu complements your existing tools.
Jozu works with
-
Identity (Okta, Entra, Keycloak)
-
Data Loss Prevention (Forcepoint, Proofpoint)
-
SIEM and SecOps tools
-
Code and container scanners (Snyk, Trivy, Chainguard)
Jozu doesn't change
-
Model training (MLFlow, Weights & Biases)
-
Model inference (KServe, Ray)
-
Prompt engineering tools
-
Model observability (Arize, HiddenLayer)
From a laptop to an air-gapped cluster
Jozu Hub deploys to your Kubernetes environment, on-prem or private cloud. Agent Guard runs on desktops, servers, and edge devices. Both are fully functional in air-gapped and DDIL environments: policies enforce locally, records are kept locally, and everything syncs when connectivity returns. Jozu has no SaaS dependencies, meaning we never see your data, it's completely private and sovereign.
OTHER SAAS SOLUTIONS
YOUR
ENVIRONMENT
- Your data and outputs transit the internet
- Enforcement depends on their uptime and your link to it
- Audit records sit in someone else's tenant
YOUR ENVIRONMENT
- Your data stays on your infrastructure
- Policy enforces locally, with no phone home
- Audit records are yours, cryptographically chained
AI Creates Risk Faster
Than Policy Can React
All of these are already used in your org, and none of them enforce your policy.
Frontier AI
When humans or AI make mistakes, your sensitive data could end up on the internet.
Vendor AI
Vendor Agents are directly integrated into your most used tools, with zero policy enforcement.

Open Source AI
Your team can't verify the safety of public AI, inviting malicious AI in through the backdoor.


What's needed is a consistent and machine enforced policy across all AI use cases.
Two use cases, one platform
Jozu was designed to give enterprises the ability to secure, govern, manage, and track their AI, regardless of where it comes from. Jozu consolidates multiple point tools, into a single platform.
Use Case 1: Frontier and Vendor AI
Frontier AI /
Vendor AI

Jozu Agent Guard
- Block malicious prompts, responses, and unvetted MCPs
- Redact sensitive data as it passes through the network
- Enforce policies even when disconnected from the network
Govern, Track,
and Manage Activity
Govern, Track,
and Manage Activity
Jozu Hub
- Administer policies centrally
- Capture and view all audit information
- Export compliance evidence
- Track Agent Guard instances, health, and connectivity
Use Case 2: Local AI Agents
Open Source /
Self-Hosted Agents


Jozu Hub
- Scan for security issues in AI artifacts
- Administer policies centrally
- Capture and view all audit information
- Export compliance evidence
- Track Agent Guard instances
Secure Deployment
to Endpoints
Secure Deployment
to Endpoints
Jozu Agent Guard
- Isolate agents in a microVM
- Guarantee only approved AI is used
- Control agent access to files and tools
- Block or redact sensitive data
- Audit all actions and changes
See how Jozu can protect your AI use
See a short demo where Jozu finds and redacts sensitive data from going into ChatGPT. Then stop Claude Code from downloading a dangerous package. Examples of real risks impacting you today.