SOVEREIGN CLOUD ARCHITECTURE

Enterprise Security without Compromise.

Jack operates with defense in depth: isolated cloud run workers, strict PostgreSQL row level security, zero LLM model retention, and verifiable SHA-256 execution proofs.

ENTERPRISE INTEGRITY

Security That Satisfies Both Founders and CISOs.

Jack is engineered with strict cryptographic boundaries. Every action is accounted for, fully auditable, and isolated by default.

Tenant Boundary Isolation

Every organization operates within an isolated Cloud SQL and Firestore tenant context. Cross workspace leakage is blocked at the database engine level.

Zero Training Policy

Customer prompts, messages, and uploaded documents are never used for model training or retained beyond request execution lifecycles.

PHI / HIPAA Compliant Lane

Restricted healthcare data routes through isolated redaction pipelines inspired by PriorZap with audited business associate agreements.

Cryptographic Audit Receipts

Every dispatch produces an immutable receipt logging the requesting user, policy version, execution duration, and cryptographic output hash.

Governed OAuth Transport

Nango connectors operate with least privilege permission scopes. Revoke individual tool grants instantly without breaking workspace identity.

Sovereign Deployment Options

Enterprise customers can peer Jack with their private Google Cloud VPC, ensuring data never leaves approved geographical infrastructure.

Compliance & Data Handling Matrix

Standard / PolicyEnforcement LevelAudit Mechanism
Data RetentionZero Retention on InferenceEphemeral worker teardown after request settlement
Tenant IsolationCloud SQL PG18 RLSDeterministic tenant predicate required on all queries
PHI / HIPAAPriorZap Governed LaneAutomatic de-identification & BAA on Sovereign tiers
OAuth SecurityNango Managed Credential ProxyLeast privilege scopes with instant revocation
Execution ProofsImmutable Cryptographic ReceiptsSHA-256 payload and artifact hash verification