Prove the model in production
is the one you approved.
Jozu extends the DevOps security practices you already trust to AI/ML: tamper-evident packaging, scanning across nine vulnerability classes, policy-gated deployment, and one cryptographically chained audit trail. Built for on-prem and air-gapped Kubernetes environments.
Already Using KitOps?
Jozu extends the open source packaging you're already using with enterprise
security and governance capabilities:
- Multi-scanner vulnerability analysis
- Policy enforcement across environments
- Cryptographically-signed audit trails
- Detailed compliance reporting
Your existing KitOps workflow, with added production-grade controls.
Enterprise support for KitOpsThe gap between "it works" and "we can prove it"
Data scientists build models with notebooks and public APIs. Production asks harder questions: which models are running, who approved them, and does the artifact serving traffic match the artifact that was scanned? Most organizations answer with manual process, spreadsheets, and trust. That is exactly where audits fail and incidents start.
-
Unverified
No cryptographic verification between what data scientists trained and what gets deployed
-
Unscanned
Models reach production without the vulnerability scanning that's standard for application code
-
No Lineage
Can't trace production models back to the training data, code, and dependencies that created them
-
Manual
Audit preparation requires manually reconstructing lineage from S3 file names, Slack messages, and dev tickets
-
Scattered
Rollback decisions depend on finding the person who knows the right model version
-
Ungoverned at runtime
Even verified models become ungoverned once they're running as agents. No tool-level access control. No policy enforcement on MCP server invocations. No human-in-the-loop for high-risk actions.
Jozu Provides. Core Security Capacities.
Stop stitching together tools to secure ML models in production. Jozu provides tamper-evident packaging, vulnerability scanning, policy enforcement, and audit trails, deployable in air-gapped environments or behind your firewall.
-
Establish cryptographic integrity
- Automated audit trails with cryptographic verification
- SBOM generation and signed security reports
- Complete chain of custody from training to production
-
Prevent a wide range of vulnerabilities
- Supply chain attacks with malicious model files and data poisoning
- Content safety violations with toxic prompts
- Behavioral vulnerabilities like prompt injection and jailbreaking
- Adversarial robustness against evasion attacks
- Privacy risks from data leakage and inferred membership
- Model integrity risks from backdoors and poisoning
-
Block vulnerable models before deployment
- CVE scanning of all model dependencies
- Policy-based deployment gates
- Automated blocking with audit trail
- Tamper-evident, Hardened ModelKits
-
Prove compliance without manual work
- Automated audit trails with cryptographic verification
- SBOM generation and signed security reports
- Complete chain of custody from training to production
-
Deploy anywhere with consistent security
- Full functionality in air-gapped environments
- No external API dependencies
- Works with existing enterprise security infrastructure
ModelKits:
Immutable, Versioned, Secure
Instead of managing ML projects as files scattered across separate disconnected repositories, Jozu tracks and versions them together.
-
1
Package models as immutable artifacts:
Jozu builds on KitOps, the CNCF open source project for ML packaging, adding enterprise security and governance capabilities. Models, dependencies, and metadata get wrapped into OCI-compliant ModelKits with cryptographic signatures - replacing mutable files with versioned, verifiable artifacts. -
2
Scanned across nine vulnerability classes before anything ships:
Every ModelKit is scanned before deployment for the failure modes unique to AI artifacts: malicious code execution on load, backdoored model behavior, data poisoning, adversarial robustness gaps, prompt injection, sensitive data leakage, content safety failures, license and compliance violations, and dependency CVEs. Results are attached to the artifact as signed attestations, and policy gates block anything that fails: no manual review, no exceptions by default. -
3
Connect production workloads directly to source artifacts:
Each ModelKit has a SHA digest that matches the deployed model's ID in Kubernetes. Need to trace a production model back to training? The SHA connects directly to the specific model file. Rollback means selecting the exact ModelKit SHA, not guessing which S3 file matches production. -
4
Deploy with your existing tools - or use ours:
ModelKits work with standard Kubernetes deployments, KServe, and Kubeflow. Or deploy using Jozu's hardened rapid inference containers (RICs) for faster performance and reduced attack surface.
-
1
Connect production models to their source
Every model or agent in production maps directly to the exact training data, code, dependencies, and configuration that created it. When a model behaves unexpectedly or needs investigation, you have immediate answers instead of reconstructing history from disparate logs and developer memory. -
2
Prevent security incidents before they happen
Policy gates enforce your security requirements automatically across every environment: dev, staging, prod, edge. Models with critical CVEs, license conflicts, or missing signatures cannot deploy, eliminating the visibility and security gaps that cause production incidents. -
3
Evidence without the evidence hunt
Because every change, access, and deployment is captured in cryptographically chained audit logs, the evidence for NIST, HIPAA, SOX, GDPR, and ISO 42001 reporting is already assembled when the auditor asks. Export comprehensive change logs and signed security attestations as source data, with no manual preparation. -
4
Maintain security in air-gapped environments
Full scanning, signing, and audit capabilities work offline with no external dependencies. Deploy Jozu to isolated networks, edge devices, or classified environments while maintaining the same security controls.
Customer Validation
Jozu's technology is used by US and European governments, and global enterprises in every vertical.
AI/ML Security for Regulated Industries
Healthcare & Pharma
Meeting FDA validation and HIPAA requirements for ML models
What Jozu provides:- Complete audit trails required for GxP compliance
- Traceability for quality system requirements
- Documentation for regulatory submissions
- Tamper-evident logging for inspections
Financial Services
Ensuring model governance and compliance
What Jozu provides:- Immutable audit trails for SOX compliance
- Cryptographic verification of model integrity
- Complete chain of custody from development to production
Government & Defense
Governing AI in secure, air-gapped, and DDIL environments
What Jozu provides:- Complete air-gapped operation, with policies enforced locally and no connectivity dependency
- Agent Guard governs agent behavior on edge devices, tactical networks, and classified environments
- CDAO Tradewinds Awardable (Feb 2026)
Request your free Jozu trial
Interested in testing Jozu in your private environment? Download the Helm Chart, and start your 2-week trial.
-
STEP 1
Install
Jozu Hub can be installed in your environment in just 1-hour, with no disruptions to existing workflows. We suggest taking a baseline measurement of current deployment times and security gaps, to benchmark against.
-
STEP 2
Evaluate
Once installed, you can run real-world tests with your models and infrastructure for up to 2-weeks. This will allow you to measure Jozu's performance against your existing tools and processes.
-
STEP 3
Review
At the end of your 2-week trial our team will work with you to review your results, and help you quantify improvements and ROI. This includes an implementation and roadmap discussion.
Works with Your Existing Tools
-
KServe for model serving
-
Kubeflow, Argo, or other CI/CD pipelines
-
Your current OCI registry (or use Jozu Hub)
-
Existing RBAC and authentication systems
When your models ship inside agents
The models you govern today will be calling tools tomorrow. The same platform that gates artifacts before deployment governs agents at runtime: tool-level policy, human approval for high-risk actions, and the same single audit record. The AI supply chain work you do now becomes the admission control for your runtime.
FAQs
Let us help you with
some of your frequently
asked questions
How does Jozu Hub help us comply with the EU AI Act using CNCF standards?
Jozu’s focus is on speeding the data gathering needed for any AI-related compliance. Jozu includes provenance tracking for all models on its platform, from the initial development through their production usage and into retirement. This includes not only the models but the datasets, prompts, and codebases for each. Jozu provides automatic model signing, comprehensive versioning, and audit logging that captures changes in permissions, ownership, and participation. Jozu produces the provenance, versioning, and audit evidence that AI-related compliance work consumes, without manual preparation.
What security scanning is performed on models before they enter our CI/CD pipeline?
Model scanning happens automatically when ModelKits are pushed to Jozu Hub. The platform scans across nine vulnerability classes: malicious code execution on load, backdoored model behavior, data poisoning, adversarial robustness gaps, prompt injection, sensitive data leakage, content safety failures, license and compliance violations, and dependency CVEs. Jozu can block deployments or pulls if SHA digests don't match signatures, ensuring only validated models reach production. This automated validation replaces manual security reviews that slow down deployment cycles. All scan results are tracked historically, so you can see how your security posture has changed across model versions and download reports for compliance audits.
How does the SBOM (Software Bill of Materials) work with ModelKits in our pipeline?
AI SBOMs can be built using SPDX 3, the industry standard format. When Jozu can generate an AI SBOM and signed provenance attestation documenting exactly what was included and who built it. This supply chain security approach means you know the complete contents of every deployed artifact. AI SBOMs are stored with each version and can be exported for your security tools or compliance reporting. This eliminates the "what's actually in production" uncertainty that creates security and audit risks.