
AI supply chain security and runtime governance platform for AI artifacts.
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
Jozu is a cybersecurity company focused on AI supply chain security and runtime governance. The company builds infrastructure for securing and operationalizing AI models throughout their lifecycle, from packaging and distribution to deployment and execution. Their core product is Jozu Hub, a registry that stores AI artifacts as ModelKits — OCI (Open Container Initiative) artifacts that bundle models, configurations, skills, prompts, datasets, and metadata into a single signed package. Hub scans every artifact using five integrated scanners that check for serialization attacks, prompt injection vulnerabilities, adversarial robustness issues, and other AI-specific vulnerability classes. Scan results are produced as signed attestations that travel with the artifact. A second key product is Jozu Agent Guard, a secure runtime environment for AI that runs as a MicroVM on laptops, edge devices, or IoT hardware, or as a Kata Container in Kubernetes clusters. Agent Guard re-verifies artifacts at the moment of execution against separately authored and signed policy artifacts, enabling enforcement independent of the build pipeline. It supports air-gapped environments, governs tool invocations via ToolPolicy for MCP tools and agent harnesses, applies egress controls, and maintains a cryptographically chained tamper-evident audit log. Policies in Jozu are OCI artifacts themselves — separately authored, signed, and distributed outside the build pipeline — so a compromised build environment cannot produce or approve its own policy attestations. Jozu targets enterprises deploying AI models and agents, particularly those concerned with supply chain integrity, runtime behavioral governance, and compliance. The company explicitly positions its platform as complementary to existing IAM and DLP tools, filling the gap specific to AI artifact security that those tools were not designed to address.