All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Jozu described itself three ways in ten months: an enterprise AI orchestration platform in May 2025, a DevSecOps platform for enterprise AI that October, and an AI assurance company in March 2026. The company pivoted toward security budgets, layering vulnerability scanning, signing, and policy enforcement onto KitOps, its open-source project that packages AI models, agents, and the MCP servers that give agents tools into versioned, signed bundles. The products are concrete: Jozu Hub, an on-premises registry with scanning and audit trails, and Agent Guard, a runtime Jozu describes as isolating safety rules from the agents it governs. Jozu still has to tell buyers which budget line pays. The loudest proof point, KitOps downloads, measures developer adoption rather than security purchases.
| Description | Jozu secures AI supply chains and agent runtimes: its on-premises Jozu Hub registry scans, signs, and version-controls models, agents, and MCP servers packaged as OCI artifacts by its open-source KitOps project, and its Agent Guard runtime enforces policy on agent actions. | [f1] |
|---|---|---|
| Founded | 2023 | [f2] |
| Latest funding | $4M seed (announced May 2025) | [f3] |
| Product | What it does |
|---|---|
| Jozu Hub | On-premises AI model registry that stores models, agents, and MCP servers as OCI ModelKits, scans them for vulnerabilities, signs attestations, and records audit trails for deployment. |
| Jozu Agent Guard | Zero-trust AI runtime that executes agents, models, and MCP servers in isolated environments with tool-level policy enforcement and cryptographically chained audit logs. |
| KitOps | Open-source CNCF sandbox project that packages AI models, datasets, code, and configuration into versioned, signable OCI artifacts called ModelKits. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Jozu Hub packages and scans AI models, agents, and MCP servers as OCI ModelKits and signs attestations, and Agent Guard enforces runtime policy on agent tool calls. These capabilities are mapped to the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Jozu homepage: agent and model security from supply chain to runtime | official | 2026-07-03 |
| f2 | Brightspark investor blog (Jozu founded 2023, Toronto) | press | 2026-07-16 |
| f3 | PR Newswire (Jozu announcement): $4 million seed led by HalfCourt Capital | press | 2026-07-03 |
| f4 | Jozu (AI Defense Matrix Catalog): on-prem AI model registry, mapping adopted from the catalog | other | 2026-07-03 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Jozu homepage: agent and model security from supply chain to runtime; logo wall image alts name Vantedge, DVS, PNNL “Jozu's technology is used by the US government, European government, and global enterprises in every vertical.” | official | 2026-07-03 |
| s2 | Jozu Hub page: on-prem Kubernetes platform, supports Llama, Mistral, Phi, Qwen; vendor claims 10x faster deployment and a 41% acceleration “Tamper-proof storage and deployment, automated vulnerability scanning, attestations, and detailed audit trails. Your models and data stay on-premises. Supports Llama, Mistral, Phi, Qwen, and every major model format.” | official | 2026-07-03 |
| s3 | Jozu Agent Guard page: agents take actions, Agent Guard governs them “Tool-level policy enforcement, isolated execution environments, and cryptographic audit trails. Centrally controlled but locally enforced from the desktop to the edge.” | official | 2026-07-03 |
| s4 | Jozu company page: image alts name Brad Micklea, Co-founder and CEO, Gorkem Ercan, Co-Founder and CTO, Jesse Williams, Co-Founder and COO “Jozu Assessed Awardable for Department of War Work in the CDAO’s Tradewinds Solutions Marketplace” | official | 2026-07-03 |
| s5 | Jozu pricing: free Sandbox tier; compare pages target Docker Hub, MLflow, SageMaker, Weights and Biases “Test out a limited-feature hosted Jozu Hub Free for open source and personal projects” | official | 2026-07-03 |
| s6 | KitOps project site: Cosign signing, SBOM evidence; ModelKits store in Docker Hub, ECR, GCR, Harbor, Artifactory, or Jozu Hub “KitOps was built first, then it's approach was formalized into the CNCF's ModelPack spec with contributors from Jozu, Red Hat, PayPal, ANTGroup, and ByteDance.” | official | 2026-07-03 |
| s7 | Jozu privacy policy: legal entity “Jozu is a product of Akara Technologies Inc., a Delaware corporation doing business as Jozu” | official | 2026-07-03 |
| s8 | PR Newswire: Jozu raises seed to scale Enterprise AI Orchestration Platform, round led by HalfCourt Capital with Mozilla Ventures participating “today announced it has raised $4 million in seed funding” | press | 2026-07-03 |
| s9 | Brightspark Ventures investor blog: founded 2023, HQ Toronto, Ercan Red Hat Distinguished Engineer and Eclipse JDT creator, Williams AWS, Docker, Red Hat GTM “Brad previously co-founded Codenvy (acquired by Red Hat) and served as GM of Amazon API Gateway” | press | 2026-07-03 |
| s10 | Help Net Security: Jozu Agent Guard targets AI agents that evade controls (March 17, 2026) “Jozu has announced the launch of Jozu Agent Guard, a zero-trust AI runtime that executes agents, models, and MCP servers in secure environments with built-in policy enforcement and guardrails that cannot be disabled.” | press | 2026-07-03 |
| s11 | The New Stack: Open Source KitOps Turns DevOps Pipelines Into MLOps Pipelines (hands-on walkthrough, June 2024) “This article explores KitOps, an open source project that bridges this gap by allowing you to leverage your existing DevOps pipelines for MLOps tasks through the use of ModelKits.” | press | 2026-07-03 |
| s12 | GitHub cncf/sandbox issue 313, [Sandbox] KitOps: closed 2025-03-04 with the gitvote/passed label (CNCF sandbox acceptance vote) “"closed_at": "2025-03-04T14:16:53Z"” | research | 2026-07-03 |
| s13 | CNCF blog member post by Gorkem Ercan, CTO, Jozu: KitOps 1.0 release, proven in production and looking to CNCF (January 31, 2025) “The merry band of maintainers and contributors at the KitOps project is happy to announce the 1.0 release of KitOps.” | press | 2026-07-03 |
| s14 | CNCF blog by Jesse Williams (Jozu), Sachi Desai (Microsoft), and others: Standardizing AI/ML Workflows on Kubernetes with KitOps, Cog, and KAITO “KitOps, a CNCF Sandbox project, was designed to bring security, control, and ease-of-use to the AI/ML supply chain.” | press | 2026-07-03 |
| s15 | Business Wire: Agent Guard launch March 2026, and Jozu Assessed Awardable for Department of Defense Work in the P1 Solutions Marketplace “Jozu, the AI assurance company behind KitOps, a CNCF project with more than 240,000 downloads, today announced the launch of Jozu Agent Guard” | press | 2026-07-03 |
| s16 | GitHub API, kitops-ml/kitops: Apache-2.0 license, active (not archived), created February 2024 “An open source DevOps tool from the CNCF for packaging and versioning AI/ML models, datasets, code, and configuration into an OCI Artifact.” | official | 2026-07-03 |
| s17 | Jozu security page: AI Security and Governance for Kubernetes (product page with EU AI Act compliance FAQ) “AI SBOMs are stored with each version and can be exported for your security tools or compliance reporting.” | official | 2026-07-03 |
| s18 | Red Hat newsroom (2017): Red Hat to acquire Codenvy “Red Hat to Acquire Codenvy, Provider of Agile and Cloud-Native Development Tools” | official | 2026-07-03 |
| s19 | Jozu trust-surface probe 2026-07-03: trust. and security. subdomains do not resolve, /trust and /compliance 404, /security is a product page, no badge files | official | 2026-07-03 |
| s20 | Business Wire (Jozu announcement, October 2025): building a DevSecOps platform for enterprise AI, DSV standardized on KitOps across 90 plus offices “the ModelPack specification, now hosted under the Cloud Native Computing Foundation (CNCF) and backed by PayPal, ByteDance, ANT Group, and Red Hat” | press | 2026-07-03 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Jozu homepage: agent and model security from supply chain to runtime; logo wall image alts name Vantedge, DVS, PNNL “Jozu's technology is used by the US government, European government, and global enterprises in every vertical.” | official | 2026-07-03 |
| s2 | Jozu Hub page: on-prem Kubernetes platform, supports Llama, Mistral, Phi, Qwen; vendor claims 10x faster deployment and a 41% acceleration “Tamper-proof storage and deployment, automated vulnerability scanning, attestations, and detailed audit trails. Your models and data stay on-premises. Supports Llama, Mistral, Phi, Qwen, and every major model format.” | official | 2026-07-03 |
| s3 | Jozu Agent Guard page: agents take actions, Agent Guard governs them “Tool-level policy enforcement, isolated execution environments, and cryptographic audit trails. Centrally controlled but locally enforced from the desktop to the edge.” | official | 2026-07-03 |
| s4 | Jozu company page: image alts name Brad Micklea, Co-founder and CEO, Gorkem Ercan, Co-Founder and CTO, Jesse Williams, Co-Founder and COO “Jozu Assessed Awardable for Department of War Work in the CDAO’s Tradewinds Solutions Marketplace” | official | 2026-07-03 |
| s5 | Jozu pricing: free Sandbox tier; compare pages target Docker Hub, MLflow, SageMaker, Weights and Biases “Test out a limited-feature hosted Jozu Hub Free for open source and personal projects” | official | 2026-07-03 |
| s6 | KitOps project site: Cosign signing, SBOM evidence; ModelKits store in Docker Hub, ECR, GCR, Harbor, Artifactory, or Jozu Hub “KitOps was built first, then it's approach was formalized into the CNCF's ModelPack spec with contributors from Jozu, Red Hat, PayPal, ANTGroup, and ByteDance.” | official | 2026-07-03 |
| s7 | Jozu privacy policy: legal entity “Jozu is a product of Akara Technologies Inc., a Delaware corporation doing business as Jozu” | official | 2026-07-03 |
| s8 | PR Newswire: Jozu raises seed to scale Enterprise AI Orchestration Platform, round led by HalfCourt Capital with Mozilla Ventures participating “today announced it has raised $4 million in seed funding” | press | 2026-07-03 |
| s9 | Brightspark Ventures investor blog: founded 2023, HQ Toronto, Ercan Red Hat Distinguished Engineer and Eclipse JDT creator, Williams AWS, Docker, Red Hat GTM “Brad previously co-founded Codenvy (acquired by Red Hat) and served as GM of Amazon API Gateway” | press | 2026-07-03 |
| s10 | Help Net Security: Jozu Agent Guard targets AI agents that evade controls (March 17, 2026) “Jozu has announced the launch of Jozu Agent Guard, a zero-trust AI runtime that executes agents, models, and MCP servers in secure environments with built-in policy enforcement and guardrails that cannot be disabled.” | press | 2026-07-03 |
| s11 | The New Stack: Open Source KitOps Turns DevOps Pipelines Into MLOps Pipelines (hands-on walkthrough, June 2024) “This article explores KitOps, an open source project that bridges this gap by allowing you to leverage your existing DevOps pipelines for MLOps tasks through the use of ModelKits.” | press | 2026-07-03 |
| s12 | GitHub cncf/sandbox issue 313, [Sandbox] KitOps: closed 2025-03-04 with the gitvote/passed label (CNCF sandbox acceptance vote) “"closed_at": "2025-03-04T14:16:53Z"” | research | 2026-07-03 |
| s13 | CNCF blog member post by Gorkem Ercan, CTO, Jozu: KitOps 1.0 release, proven in production and looking to CNCF (January 31, 2025) “The merry band of maintainers and contributors at the KitOps project is happy to announce the 1.0 release of KitOps.” | press | 2026-07-03 |
| s14 | CNCF blog by Jesse Williams (Jozu), Sachi Desai (Microsoft), and others: Standardizing AI/ML Workflows on Kubernetes with KitOps, Cog, and KAITO “KitOps, a CNCF Sandbox project, was designed to bring security, control, and ease-of-use to the AI/ML supply chain.” | press | 2026-07-03 |
| s15 | Business Wire: Agent Guard launch March 2026, and Jozu Assessed Awardable for Department of Defense Work in the P1 Solutions Marketplace “Jozu, the AI assurance company behind KitOps, a CNCF project with more than 240,000 downloads, today announced the launch of Jozu Agent Guard” | press | 2026-07-03 |
| s16 | GitHub API, kitops-ml/kitops: Apache-2.0 license, active (not archived), created February 2024 “An open source DevOps tool from the CNCF for packaging and versioning AI/ML models, datasets, code, and configuration into an OCI Artifact.” | official | 2026-07-03 |
| s17 | Jozu security page: AI Security and Governance for Kubernetes (product page with EU AI Act compliance FAQ) “AI SBOMs are stored with each version and can be exported for your security tools or compliance reporting.” | official | 2026-07-03 |
| s18 | Red Hat newsroom (2017): Red Hat to acquire Codenvy “Red Hat to Acquire Codenvy, Provider of Agile and Cloud-Native Development Tools” | official | 2026-07-03 |
| s19 | Jozu trust-surface probe 2026-07-03: trust. and security. subdomains do not resolve, /trust and /compliance 404, /security is a product page, no badge files | official | 2026-07-03 |
| s20 | Business Wire (Jozu announcement, October 2025): building a DevSecOps platform for enterprise AI, DSV standardized on KitOps across 90 plus offices “the ModelPack specification, now hosted under the Cloud Native Computing Foundation (CNCF) and backed by PayPal, ByteDance, ANT Group, and Red Hat” | press | 2026-07-03 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.