Security is the operating-cost floor,
not a feature checklist
Three deployment shapes (managed cloud / customer VPC / air-gapped on-prem). BYOK encryption. Hash-chain audit trail. 8-framework regulatory mapping. Built for engineering-led mid-market IT teams that need to defend the AI estate at board, audit, and procurement review.
Audit-evidence emission is the operating-cost floor: if a workflow can't be instrumented for audit evidence, we won't take it on. Non-negotiable across phases.
The framework underneath
10-Layer Governance — the same framework we use internally and with every customer
The security capabilities below aren't ad-hoc features. They sit inside a 10-layer governance framework — Identity & Access, Audit Trail, Data Governance, Human Oversight, Model Governance, Tool Governance, Compliance, Cost Controls, Observability, and Incident Response — that JieGou uses to operate AI for paying customers and to assess every customer engagement. Same framework on both sides of the table.
Cyber underwriting readiness
Your cyber underwriter is starting to ask about AI.
Industry analysts and broker commentary now identify AI governance maturity as a stated underwriting factor in mid-market cyber renewals. Aon (2026): "Underwriting reviews are now sharply focused on control maturity, vendor dependencies, AI use, and privacy practices." Lockton (Dec 2025): "Underwriters are scrutinizing board and senior management oversight of AI governance."
We've published a free operator-grade brief mapping the 10-Layer framework to the six AI question categories appearing in 2026 mid-market submissions. Anchored on Marsh / Aon / Lockton / NYDFS citations. No vendor-specific premium-discount claims — operator-honest about what documented governance does and doesn't deliver.
SOC 2 Audit Status
SOC 2 Type II report issued August 2026 by Advantage Partners: unqualified opinion, no exceptions noted, covering the Security trust services criteria over the period March 23 – June 23, 2026. Continuous compliance monitoring via Vanta remains active between audit periods. Report available under NDA.
Completed with a certified vendor.
Report issued August 2026 — unqualified opinion, no exceptions noted (Advantage Partners).
3–12 month period — starts after readiness confirmed.
One brief pairs the attestation with the discipline behind it — the SOC 2 Type II signature from outside, and our running record of publishing findings against ourselves. Written for a security diligence review. Free to cite, no email gate.
The prospective half of that record: one research cycle run under pre-registered predictions — written before any run, under a no-edit rule — where the first result refuted our own point prediction and the refutation was kept in the permanent record above the recovery. A retrospective claim cannot be diligenced; a method like this can. Free to cite, no email gate.
Everyone is about to have a gate. Almost nobody will have the receipt.
Approval-before-action has stopped being a differentiator and started being platform policy — and the gates are real now, not roadmap. One platform ships a privileged action only when an approval already exists in the session, single-use and expiring in hours. A major CRM’s seasonal release now offers per-message human approval of an agent’s outbound email, configurable three ways: review every message, review only the first, or let a rule decide. Others answered with spend ceilings and after-the-fact session transcripts. A log is written for a reader who was present. A receipt is written for someone who was not — who approved, what they could see when they did, an artifact you can show an auditor six months later. That part isn’t infrastructure. It’s a by-product of operating the work, and it’s what our hash-chain audit trail produces on every engagement. The gate itself is still becoming infrastructure — it just didn’t this month, and we treat that as a reprieve on a schedule, not a reversal.
The gate itself isn’t our answer to oversight, either. Anthropic published the number that ends per-action prompting: users approve 97% of permission prompts. Our agents are instead confined to the reversible half of the work — they gather, draft, propose, and prepare the decision in full, and they never hold the irreversible step. Reversible proceeds; judgment waits. There is nothing to rubber-stamp, because the risky act was never the agent’s to take. And the gate was never a safety mechanism — it is an accountability mechanism: a machine-reviewed action can be perfectly safe and still leave nobody accountable for it. Vendors will keep moving where review defaults sit; who answers for the send doesn’t move with them.
And you don’t have to take our word for the receipt. The schema our records are written to is published. The verifier that checks them is open source and shares zero lines of code with our product — it implements the hash logic from the published spec, not from our source, and proves itself against a golden vector. Even the census of what our audit layer does not yet cover is published, as a number that is only allowed to shrink. A gate is a feature. An attestation a stranger can verify without us in the room is not.
And the boundary between the two halves is not fixed — it moves on evidence. Every proposal an agent makes and every decision a person renders accumulates into a record, and that record is what justifies the next increment of trust: wider drafting authority, longer unattended runs, a new channel. A task tracker can hold shared state; it cannot safely expand what an agent does unwatched. That takes the accumulated record of proposed-versus-decided — produced here as a by-product of operating. Governance isn’t the brake on delegation. It’s what earns the next one.
Infrastructure Security
Three deployment shapes; same security posture in each
JieGou supports three deployment shapes (managed cloud, customer VPC, air-gapped on-prem) so the deployment fits your governance posture rather than the other way around. All shapes encrypt in transit with TLS 1.3 and at rest with AES-256-GCM. Penetration testing is conducted by certified vendors; results shared with customers under NDA.
- Managed cloud (AWS multi-region) · customer VPC · air-gapped on-prem
- TLS 1.3 for all traffic; AES-256-GCM at rest
- Network isolation via private subnets, security groups, mTLS between services
- Certified-vendor penetration testing; results shared with customers under NDA
Application Security
24,000+ tests. 99.18% coverage. Every night.
Our test suite runs over 24,000 automated tests with a 99.18% code coverage threshold. Nightly adversarial regression testing catches prompt-injection + data-exfiltration regressions before they reach production. Dependency vulnerability scanning runs on every commit and PR. Architecture documented at /reference-architecture (7-component decomposition, 10 named failure modes).
- 24,000+ automated tests; 99.18% code coverage threshold
- Nightly adversarial regression (prompt injection, data exfiltration, jailbreak)
- Dependency vulnerability scanning on every commit and PR
- Architecture published — see /reference-architecture for component-level detail
Data Security
Your keys, your data, your audit trail
Bring Your Own Key (BYOK) encryption keeps your LLM provider keys encrypted with AES-256-GCM using your own KMS / Secrets Manager. Data residency configurable per workflow (US / EU / APAC / private region). Automatic PII / PHI detection routes regulated fields through DLP before they reach any LLM. Audit trail is hash-chain-signed (HMAC) for SOX / FDA / EU AI Act evidentiary contexts; export to your SIEM (Splunk / Sentinel / syslog).
- BYOK with AES-256-GCM; provider keys in your KMS / Secrets Manager
- Per-workflow data residency (US / EU / APAC / private region)
- Automatic PII / PHI detection routes regulated fields through DLP
- Hash-chain-signed audit trail (HMAC) with SIEM export
Compliance + Regulatory Mapping
Eight frameworks. One operating substrate.
Compliance posture is configured per-engagement under our 10-Layer Governance framework (published at /10-layer-assessment), not via single-toggle SaaS presets. The substrate maps onto SOC 2 Common Criteria (CC6 + CC7), HIPAA (BAA-eligible), SOX (hash-chain audit trail), GDPR (right-to-erasure + data-residency), EU AI Act (risk-tier + conformity-assessment), NIST AI RMF (govern + map + measure + manage), and ISO/IEC 42001 (AI Management System). FedRAMP-ready configuration available for government customers under the Reference Architecture air-gapped deployment.
- SOC 2 Common Criteria (CC6 Logical & Physical Access + CC7 System Operations)
- HIPAA-aligned workflows (BAA-eligible) + SOX hash-chain audit-trail integrity
- GDPR (right-to-erasure, data-residency) + EU AI Act risk-tier mapping
- NIST AI RMF + ISO/IEC 42001 + FedRAMP-ready air-gapped deployment
Vulnerability Disclosure
Responsible disclosure. Operator-transparent communication.
Security researchers can report vulnerabilities to security@jiegou.ai. We acknowledge within 48 hours, issue CVEs for confirmed vulnerabilities, and publish quarterly security reviews including any incidents + remediation timelines. Bug bounty available — see the responsible disclosure policy for scope + rewards.
- security@jiegou.ai for vulnerability reports
- 48-hour acknowledgment SLA
- CVE issuance for confirmed vulnerabilities; quarterly security review published
- Responsible disclosure policy + bug bounty scope →
Industry Alert
Why self-hosted doesn't mean secure
The open-source automation platform n8n disclosed 21+ security vulnerabilities in February 2026 — including 7 critical (CVSS 9.4–10.0) and 4 independent remote code execution vectors. Most critically, CVE-2026-25049 bypasses a December 2025 sandbox fix within 3 months — proving the issues are architectural, not patchable. National cybersecurity agencies — Singapore CSA and Canadian CCCS — have issued formal advisories. Censys identified 26,512 exposed n8n instances on the public internet.
JieGou's substrate posture vs unmaintained self-hosted
Self-hosted unmaintained risks
- 3 independent RCE vectors (expression, SQL, task runner)
- Government advisories (Singapore CSA, Canadian CCCS)
- SSO bypass, SQL injection, webhook forgery
- No SOC 2 audit, basic RBAC, no audit-trail integrity
JieGou operating substrate
- Three deployment shapes (managed cloud / VPC / air-gapped on-prem)
- SOC 2 Type II report issued (2026); continuous monitoring via Vanta
- 6 roles, 20 granular permissions, SAML/OIDC, per-agent identity
- Hash-chain audit-trail integrity; GDPR data export/deletion; SIEM export
Data as of February 2026
Run the 10-Layer Assessment. Or schedule the discovery call.
10-Layer Assessment is the framework we use internally and with every customer — free to run, no sales-call condition. Discovery call is 30 min, no deck, no demo. Either path; honest either way.