Jointli is a community of people who came up in cybersecurity. Some of us are practitioners, some run operations, some handle account support. What we share is a way of working: the same rigor, scaled to fit whoever we are working with, from growing companies to global enterprises.
Mapping tools, monitoring dashboards and control checklists handle the mechanical share of AI governance. What they hand back is the judgment: whether your safeguards are reasonable for your risk, and whether you can show it. That is the part we do.
The work rests on duty of care risk analysis: impact weighed against likelihood, criteria stated openly, the balancing test shown. That is the difference between an assessment a client likes and one that survives a regulator, an auditor, or opposing counsel.
The EU AI Act, NIST AI RMF, ISO/IEC 42001, NIST 800-53 and CSF, ISO 27001 and 27002, CIS Controls and OWASP, run as one coherent method instead of nine separate checklists.
Every engagement is delivered through a Governed AI Assistant inside a Secure Enclave: an AI system constrained by an explicit workflow, explicit authority rules, and an evidence trail. It never signs, sends, or spends. A person stays accountable for every conclusion.
Figuring out how you adopt AI responsibly, and then helping you do it. You enter where you are and climb only as far as you need. Work you have already done gets credited into the next rung rather than repeated. Open any step to see what it is.
A directional, in depth read on where automation would actually pay for you, and which rules you are already on the hook for. Short, scoped, and it stands alone.
Who it is for. Leaders who know AI matters but are not sure where to start or what they are allowed to do.
What you leave with. A map of the opportunity and the obligations, in plain language. Not a sales pitch, and no requirement to go further.
Duty of care risk analysis across the nine frameworks, with explicit risk criteria and a stated risk appetite. Most assessments are checklists. This one is a balancing test, built so you can show why your safeguards are reasonable for your risk.
Who it is for. The General Counsel and the CISO who personally carry the liability.
What you leave with. A written analysis you can put in front of a regulator, a board, an insurer or opposing counsel, with the reasoning visible rather than asserted.
Codified policies covering risk, ethics, acceptable use, model lifecycle and data handling, tailored to the regimes you answer to and written to survive a customer's procurement review.
Who it is for. Whoever has to turn "we should govern AI" into a charter, owners, and board level accountability.
What you leave with. A governing system rather than a document set. Done right it speeds the AI program up, because everyone knows what is allowed and you can prove it.
The workflows, tools and agents themselves, built where you work and kept running under governance rather than bolted to it afterward.
Who it is for. The operating leader who tried to build AI and stalled, or who wants it built right the first time.
What you leave with. Something you can actually run and actually defend. Most builds die between the pilot and production, and governance is a named reason why.
Design, build, run, improve, on your behalf and continuously supported. The most complete form of the relationship.
Who it is for. The owner or chief executive who wants the outcome of an AI operated business without hiring and holding the team to run it.
What you leave with. An operation run by the same people who governed it, accountable for the result rather than for the deliverable.
Three questions decide most of what an engagement looks like. Answer them here and you will know roughly where you sit before anyone gets on a call. Nothing is stored and nothing is sent until you choose to send it.
This is a starting point, not a quote. Where you actually land gets decided on the first call, and it is common to enter one rung lower than this suggests.
Every engagement is scoped before it starts and quoted as a single fixed fee. No hourly rates and no meter running. If the scope changes partway we requote and you decide whether to go ahead. You will know what the work costs before anyone begins it.
Three things: how much of your environment is in scope, how many frameworks you have to answer to, and whether you want a point in time assessment or an ongoing program. Those get worked out on the first call, before anyone writes a proposal.
The practitioner doing the work, an independent review of that work before it reaches you, and a written deliverable you can put in front of your board, your client or your insurer. Those are not line items and they are not billed separately.
Prior work you bring is assessed against the same standard and credited fairly into the engagement. No client is made to start over or to buy a rung they have already climbed.
You are meant to be able to check the work rather than take it on faith. The criteria are stated, the balancing test is shown, and the evidence sits behind each finding where anyone can follow it.
Duty of care risk analysis exists so that an analysis can be communicated to and accepted by authorities such as regulators and judges. Your assessment is built on that standard, which means it arrives already speaking the language of whoever will scrutinize it.
The person who did the work is never the last person to read it. Every deliverable is reviewed independently inside the collective, against the same criteria every time. That review is standard on every engagement, not an upgrade.
We do not put client names or logos on our marketing, and yours will not appear on it either. What a client tells us stays between us, which is the same discretion you would want applied to your own engagement.
There is no funnel and no automated screening. This reaches a founder, who reads it and writes back. If there is a fit, the next step is a call where we work out which rung you are on and what the engagement would cost.
You keep your own practice, your own clients, and your own name. What you get from us is the machinery that solo work usually cannot reach: real engagements, a governance system that makes the work defensible, and colleagues who have done it before.
Members are independent businesses with their own practices. There is no non-compete and no restriction on the clients you bring or keep. You come and go freely, you take your own book with you, and anything you earned on collected revenue still pays out.
Contracts, invoicing and collections sit with the firm rather than with you. It holds the client agreements and does none of the client work. The time you spend is on the work you are actually good at.
Every member gets their own Governed AI Assistant inside the Secure Enclave. It carries the standing context so you are not rebuilding the client picture every session, and it keeps an evidence trail behind every conclusion. You stay the principal. It never acts past you on anything consequential.
Every engagement is carried by three roles. You do not need a technical background to have a home here. You can hold one lane, or grow into a second later, and adding one is a conversation rather than a restart. Open a lane to see what it asks of you.
Assessments, governance and policy, builds, advisory. This is the technical lane, for the practitioners who deliver.
You get the largest share because you carry the work and your name is on the reasoning. Expect your deliverables to be reviewed by someone else in the collective before they reach a client, every time.
Finding the work, building the trust, closing it, and staying with the client through renewal. If you are good with people and know how to sell and manage an account, this is you.
No cybersecurity background required. You are paid for as long as you hold the account, not once at the close.
Running the project, holding the schedule, guarding the scope. If you are organized and run things well, this is you.
No cybersecurity background required. This is the lane that keeps a collective of independents from behaving like a collection of freelancers.
Everyone sees the whole map during onboarding, all three lanes and how the money moves through each. Only the lanes you are actually working get activated. That way you know the door exists before you want to walk through it.
Every engagement splits four ways, on the same formula for everyone. No tiers and no side deals. Everyone is paid on collection, from what the client actually paid, so nobody ever fronts their own money. Select a share to see what it covers.
There is no fee to join. Membership is by sponsorship, and it covers your Jointli email address, access to the secure workspace, the shared infrastructure, and the liability shield for the year. You bring your own laptop, insurance and taxes, the same as any independent business. The specific terms are in the member agreement, and we walk you through it on a call before you commit to anything.
Everything you sign is one document, the Collective Member Agreement, which folds the contractor terms, the confidentiality agreements and the ethics and acceptable use policies into a single packet. The bar to join is intentionally low. The bar for how we treat each other is high.
Every engagement has a written schedule that says who does what and what each role earns on it, signed before the work begins. Nobody finds out what they are getting after the fact.
Intent, analysis, options, decision, execution, verification. Your assistant carries the standing context so you are not rebuilding the client picture from scratch every session, and the evidence trail is a by-product of working rather than a chore at the end.
Payment follows collection, so no member is ever financing the firm's cash flow out of their own pocket. The schedule and the terms are in the member agreement.
Written down so you can see the whole route before you start it. Nothing here is a surprise later, and you are not committed to anything until the fourth step.
Your note goes to one of the two founders, who reads it and writes back. There is no screening step in between and no automated sequence.
We walk you through the member agreement, exactly how the money works, what membership covers and what it does not, and the kind of work you would realistically be placed on. You can end the conversation there and owe nothing.
If both sides want to go ahead you get a checklist. It is short and it never changes: the signed member agreement, which is one document rather than a stack; your own registered business with an EIN; a certificate of errors and omissions insurance matched to what you do; and the membership fee for your first year.
Nobody is provisioned before all four are true. That gate is what protects everyone already inside.
A jointli.io address as your identity on joint work, access to the Collective Infrastructure, and your own Governed AI Assistant issued to you and running under your control.
You are walked through all three lanes and how money moves through each, not only the one you came for. Only the lanes you are actually working get activated, and adding one later is a conversation rather than a restart.
Then a first piece of real work inside thirty days: either shadowing a live engagement end to end, or selling your first piece of joint work, depending on the lane.
There is no application funnel and no automated screening. This reaches a founder, who reads it and writes back. If there is a fit, the next step is a call where we walk you through the member agreement, the economics, and what a first engagement would look like.