Jio assumes a trusted Linux host and treats guest workloads as hostile. KVM isolates the guest from ordinary host processes, but it does not hide guest data from the host administrator.
No confidential-computing claim
Jio is not confidential, attested, or operator-blind. Do not run data that your Jio operator is not authorized to access.
Current protections
- one KVM microVM per running session;
- immutable, content-addressed runtime templates;
- private copy-on-write guest memory;
- fresh session identity and entropy after restore;
- per-session SSH keys and generation checks; and
- authenticated control-plane requests.
These controls do not remove the trusted host from the security boundary.
SOC 2 Compliance
Jio's public documentation does not currently provide a SOC 2 report. Treat the service as unverified for SOC 2-dependent workloads unless your operator provides a current report covering the service you use.
Current status
MicroVM isolation is a technical control, not proof of SOC 2 compliance. Do not represent Jio as SOC 2 compliant without a current independent audit report.
SOC 2 evaluates organizational controls and their operation over time. A review would need evidence for access management, change control, incident response, monitoring, vendor management, and data retention—not only runtime isolation.
Ask your Jio operator for the current report, its scope, audit period, bridge letter if applicable, and any customer responsibilities before approving a regulated workload.
Data handling
Review Data handling for operator access, credentials, retention, and deletion.
Report a vulnerability
Email support@jiovanni.sh with the affected Jio version, impact, and reproduction steps. Do not open a public issue or include live API keys, private keys, or other people's data.
Security fixes target the latest experimental release. Upgrade before checking whether a previously reported issue is resolved.