JasperX

jasperx · security

Security & Trust

The principles

Three rules the product is built on:

The plant never depends on us.

JasperNode controls equipment autonomously. Cloud outage, subscription lapse, or our company having a bad day: none of it stops your process.

A human approves what reaches the field.

AI-driven changes to live systems pass through the deploy gate. The AI proposes; you dispose.

Everything is on the record.

Every change carries who, when, and how. AI changes record the exact model and conversation that produced them, so any decision can be traced years later.

Beta doesn't mean careless. The beta channel moves fast on platform features. It does not move fast on the deploy gate, the audit trail, or the runtime's independence from the cloud; those hold on every channel.

Network posture

Nodes make outbound connections only. No inbound ports, no port forwarding, no VPN concentrator, no device exposed on the plant network. Remote access to node web services runs through an authenticated, audited tunnel on that single outbound connection.

Data residency

Hosted on Google Cloud in Sydney. Program data, tag history, and audit logs are stored in Australia; some traffic may transit Google-managed infrastructure in other regions.

The exception is the AI. Prompts and program code sent to the AI are processed by our providers, Anthropic (Claude) and xAI (Grok), under commercial API terms: neither trains on your data, and both delete API inputs and outputs within 30 days.

What JasperX is not

JasperX is not a safety instrumented system. It does not replace hardwired E-stops, safety relays, or SIL-rated functions, and we will not tell you it does. Safety-rated control stays in equipment certified for it; JasperX handles the process logic around it.

The cloud does not do real-time control. Control lives at the edge, in JasperNode, on your hardware. The cloud builds, observes, and keeps the history.

Disclosure

Found a vulnerability? [email protected]. We respond within three days, and we won't threaten researchers with lawyers. The full policy is in SECURITY.md on GitHub.