Reviewer and investor command brief

Jaga

Discreet emergency response for Bali. Built around human dispatch and resilient incident architecture.

Jaga is a Bali-first life-safety system.

A phone with a discreet safety app outside a Bali villa while a dispatcher works inside.

Brief at a glance

The reviewer frame before the architecture deep dive.

Start with the operational decision: what is live enough to inspect, what is still gated, and where human accountability sits.

Pilot status
Controlled Bali pilot in build-and-drill phase
Reviewer question
Can the panic path degrade toward people and protocol?
Human response model
Dispatcher-led review, responder offer, arrival proof, closeout
Proof posture
Local app, dispatcher, mobile, and rendered website gates passing
Open gates
Live operator drill, legal review, evidence storage, device acceptance

Architecture principle

The panic path must survive the failure of everything that is not the panic path.

Subscriptions, admin, payouts, analytics, and non-critical notifications can degrade. The distress path must degrade to dispatcher phone protocol, not silence.

How it works

Human response loop from signal to closeout.

Trigger modes include panic button, secret tap, quiet PIN, armed phrase, and Guardian Mode. A dispatcher verifies context before the record moves forward.

  1. Trigger
  2. review window
  3. dispatcher awareness
  4. responder offer
  5. arrival proof
  6. closeout

Signal demo

Three moments carry the operating model.

Discreet trigger, dispatcher handoff, and responder arrival are presented as one controlled sequence. Each frame maps to the event-log story.

  1. 01 Discreet trigger

    A customer signal enters the review window without turning setup into friction.

  2. 02 Dispatcher handoff

    The operator sees context, trigger source, and fallback path before responder movement.

  3. 03 Responder arrival

    The incident closes through arrival proof, notes, evidence references, and audit record.

System map

One operating model, five human surfaces, one source of truth.

The public site shows architecture, not the authenticated operational console. Each node has a responsibility, a boundary, and an audit surface.

01

Customer app

Panic button, secret tap, quiet PIN, armed phrase, Guardian Mode, and fallback number.

02

Dispatcher console

Human review, context brief, responder offers, evidence references, and closeout.

03

Responder app

Shift presence, offer accept or decline, navigation, arrival proof, and closeout helper.

04

Backend core

Hono API, shared contracts, domain services, Postgres and PostGIS-backed dispatch.

05

Incident event log

Append-only operational, legal, payout, and audit timeline. The timeline is the truth.

06

Evidence store

Private objects, signed access, retention metadata, and evidence read intents.

07

Ledger

Payout review, callout fees, settlements, and dispute support.

08

Partner and admin layer

Organizations, vetted units, zones, scorecards, and operator review.

09

Intelligence module

Readiness findings, Dispatcher summaries, risk hints, explanation drafts, and Operator QA findings.

Bounded modules, not premature microservices.

Jaga starts as a modular monolith. Each module owns a small truth and avoids touching another module's legal or operational boundary.

identity

Owns
Auth, profiles, PINs, trusted contacts
Never owns
Incident lifecycle

dispatch

Owns
Incidents, offers, unit presence, lifecycle
Never owns
Payout truth

evidence

Owns
Capture chunks, storage, read intents, retention
Never owns
Dispatch decisions

ledger

Owns
Payouts, fees, settlements
Never owns
Incident state

partner

Owns
Orgs, units, zones, vetting
Never owns
Broad customer PII

intelligence

Owns
AI findings, summaries, readiness, QA, drafts
Never owns
Emergency truth

Source of truth

The incident event log is the legal, operational, payout, and audit record.

Current state is a projection. The timeline is the truth. Evidence is handled with consent boundaries and private read intents.

  • Actor, timestamp, trigger source, and context.
  • Evidence references and private read intents.
  • Dispatcher notes, responder offers, arrival proof, and closeout.

Operator Intelligence Layer

AI informs. Operators decide. The event log remains truth.

AI helps the human team see what changed, what is missing, and what needs review. AI reads permitted records and produces briefs, hints, drafts, and QA findings. Humans own response, closeout, and accountability.

AI may support

Readiness findings, Dispatcher briefs, Risk hints, Missing-step prompts, Explanation drafts, QA findings, Trend reports, and Training and rubric feedback.

AI may not own

  • Incident state
  • Responder selection truth
  • Payout approval
  • Evidence access control
  • Emergency truth
  • Silent dispatch authority
  • Legal timeline rewriting
  • Customer-facing explanations without human approval
  • Operator discipline or partner penalties
  • Public safety promises
Before -> Readiness

Readiness intelligence

Prevents weak configurations before panic happens.

Outputs
readiness score, missing setup items, pilot-not-drill-ready warnings
Boundary
Never blocks the panic trigger.
During -> Dispatcher Brief

Dispatcher intelligence

Reduces operator cognitive load in the first seconds.

Outputs
dispatcher brief, trigger source, stale-event warnings
Boundary
Does not decide whether an incident is real.
After -> Explanation + QA

Explanation and QA

Makes the record understandable without rewriting truth.

Outputs
customer explanation draft, operator closeout summary, missing evidence notes
Boundary
Drafts require human approval.
Across -> Patterns + Training

Pattern intelligence

Finds recurring weak patterns across drills and incidents.

Outputs
trend report, training queue suggestions, partner coverage review hints
Boundary
Trend reports are hints, not accusations.

Human-in-the-loop policy

Readiness setup prompt Auto-show with audit

Low stakes, reversible, useful before incidents.

Dispatcher brief Auto-show with visible sources

Time-sensitive support; operator still decides.

Customer explanation draft Confirm before action

Customer-facing and sensitive.

Payout, discipline, dispatch, evidence access Human-only

High-stakes or authority-bearing actions.

Data boundary

The layer reads permitted records, allowed profile fields, incident event log entries, responder availability, approved dispatcher notes, and evidence metadata, not raw evidence by default.

It does not expose broad customer PII, secrets, signed URLs, or internal debug logs, and it makes no public safety claims.

Operator intelligence role reference

Readiness Coach

Reads
Trusted places, contacts, phrases, PIN, sound check, fallback number
Writes
Readiness findings and setup priorities
Never does
Blocks the panic trigger

Context Summarizer

Reads
Allowed profile, location, trigger source, recent events
Writes
Dispatcher incident brief
Never does
Decides whether an incident is real

Risk Pattern Assistant

Reads
Unusual routes, missed check-ins, cancelled triggers, responder gaps
Writes
Risk hints and attention flags
Never does
Silently dispatches

After-Incident Explainer

Reads
Event log, closeout, evidence metadata, approved notes
Writes
Customer explanation draft
Never does
Sends unapproved communication

Operator QA

Reads
Drills, closed incidents, timings, missing events
Writes
QA findings and operational gaps
Never does
Approves payouts

Reliability boundaries

Designed to degrade toward people and protocol.

Timing budgets are architecture goals and pilot gates. They are not public guarantees. The fallback story is the point.

Failure modes and fallback behavior
Failure mode Primary path Fallback behavior Owner
Phone offline HTTPS trigger Local retry plus dispatcher phone path Customer app
Dispatcher console stale Realtime console Event replay and on-call escalation path Dispatch
Push delayed Notification Polling and next-unit review Responder app
Responder unavailable Offer fanout Renew offer or escalate to operator review Dispatch
Evidence storage unavailable Private object store Fail closed and preserve event metadata Evidence
Provider outage Managed runtime Dispatcher phone protocol and recovery runbook Operations
A dispatcher reviews a private response handoff from an operations room near a villa.

Built around human dispatch.

Automation can prepare the handoff, but the operator record stays central: what happened, who responded, and how the incident was closed.

Review duplicate guard
Response offer lifecycle
Evidence private read intent

Pilot proof and gates

Built and tested locally, not represented as live public emergency coverage.

Jaga is being prepared as a controlled Bali pilot. It does not replace local emergency services or make public emergency coverage claims.

Pilot proof

  • Local M1 machine evidence
  • Backend integration coverage
  • Dispatcher Playwright coverage
  • Mobile trigger flows
  • Synthetic watchdog and drill artifacts
  • Customer, responder, dispatcher lifecycle coverage

Open gates

  • Live operator drill
  • Legal and store review
  • Production evidence storage review
  • External deployment approval
  • Final live-device acceptance

Review the system before the pilot expands.

The next conversations are operational: partner coverage, operator review, legal readiness, production evidence storage, and live drill design.