top of page

Introducing Jeannie: How nxtlinq Powers the Security and Governance Backend of Berify's AI Concierge

Jul 20
6 min read

Jeannie is Berify's client-facing AI concierge. Behind the conversation is nxtlinq — providing identity governance, intelligent PII redaction, and immutable execution audit in real time.


Most conversations about agentic AI focus on what the agent can do. The harder question — and the one that determines whether an AI agent can actually be trusted in a client-facing role — is what the agent is governed not to do, what data it is prevented from mishandling, and who is accountable when something goes wrong.

Jeannie, Berify's AI client service and concierge agent, was built with that question at its center. And the answer is nxtlinq.



What Is Jeannie?

Jeannie is Berify's intelligent client service agent — a conversational AI designed to assist Berify's customers with product authentication queries, account management, support requests, and service interactions. She operates as a front-line concierge, handling the kind of sensitive, identity-adjacent conversations that demand both fluency and caution.

That combination — conversational AI in a context where customers share personal information, account details, and service requests — is precisely where governance infrastructure is not optional. It is the baseline requirement for deployment.


A client-facing AI agent that handles customer identity, account data, and service requests is not a research experiment. It is a production system with real data exposure, real liability, and real customers who expect their information to be protected.


What nxtlinq Provides: The Governance Backend

nxtlinq operates as Jeannie's security and governance infrastructure — invisible to the end user, essential to safe deployment. Every message Jeannie receives, every action she takes, and every response she generates passes through nxtlinq's execution layer before and after it reaches the underlying model.


nxtlinq Capability

What It Does in Jeannie

Why It Matters

HIT — Human Identity Token

Links Jeannie's sessions to a verified Berify user

No PII inside the token — biometric reference only

AIT — AI Identity Token

Scopes exactly what Jeannie can access and execute

Per-session, time-bounded, least-privilege by design

QET — Qualified Event Tokenization

Classifies every prompt and response by severity level

High-severity events trigger redaction or escalation automatically

Intelligent PII Redaction

Strips or masks personal data before it reaches the model

Configurable by data type: name, card, ID, contact, financial

Immutable Audit Ledger

Records every agent action in a tamper-proof log

Full session lineage — who asked, what Jeannie did, what data was touched

Execution Boundary Enforcement

Prevents Jeannie from accessing data outside her scope

Enforced at token level — not dependent on agent logic


How It Works: The Execution Architecture

Every Jeannie interaction follows this governed path:

01

User Message

Berify client via Jeannie

→

02

AIT Validated

nxtlinq — scope check

→

03

PII Redacted

nxtlinq — before model

→

04

QET Classified

nxtlinq — severity rated

→

05

Model Executes

Jeannie responds

→

06

Audit Logged

nxtlinq — immutable


The critical design principle is that governance happens at the infrastructure layer — not inside Jeannie's agent logic. This means Berify's team can iterate on Jeannie's capabilities, conversational design, and product knowledge without governance being a variable. The security layer is always on, always consistent, and always enforced regardless of what Jeannie is asked to do.


"Governance at the infrastructure layer means Jeannie can evolve. The security posture doesn't have to."

— nxtlinq Architecture Principle


Intelligent PII Redaction: Protecting Customers Before the Model Sees Their Data

One of the most important — and least visible — capabilities nxtlinq brings to Jeannie is intelligent PII redaction. When a customer submits a message that contains personally identifiable information, nxtlinq's redaction layer intercepts it before it reaches the underlying model, replaces sensitive data with structured tokens, and allows the model to reason about the request without ever processing the raw PII.

This matters for several reasons. Models have memory — in-context, at minimum, and potentially beyond. A customer sharing their email address, payment information, or identification details in a conversational interface should not have that information retained, logged, or exposed through model outputs. nxtlinq's redaction layer enforces that boundary automatically.


PII Type

Raw Input

After nxtlinq Redaction

Customer name

"Show me John Smith's order"

"Show me [CUSTOMER]'s order"

Email address

"Send confirmation to j@email.com"

"Send confirmation to [EMAIL]"

Payment / card data

"Charge card ending 4242"

"Charge card ending [CARD_REDACTED]"

Government ID

"Verify passport AB1234567"

"Verify passport [ID_REDACTED]"

Phone number

"Call the client at 310-555-0192"

"Call the client at [PHONE]"

Physical address

"Ship to 123 Main St, Irvine CA"

"Ship to [ADDRESS_REDACTED]"


The redaction is intelligent, not blunt. nxtlinq identifies PII by type, replaces it with semantically meaningful tokens that preserve the agent's ability to complete the task, and maintains a secure mapping that can be used for authorized reconstruction where required. The model reasons with clean data. The customer's actual information stays protected.


QET: Classifying What's Actually Happening in Every Interaction

Not all AI interactions carry the same risk. A customer asking about product authentication status is a routine query. A customer asking Jeannie to initiate a refund, update account credentials, or access order history for a third party is a different conversation entirely.

nxtlinq's Qualified Event Tokenization (QET) layer classifies every prompt and every inference response by severity level in real time. This classification is what drives the right response to different types of interactions:


Standard severity — routine queries proceed without interruption. Response logged, session attributed, audit record created.

Elevated severity — agent continues but human review queue is flagged. Interaction marked for post-session audit.

High severity — agent action paused, escalation triggered, or response blocked. Human-in-the-loop required before execution proceeds.


This tiered classification means Jeannie can handle high volumes of routine customer service interactions efficiently — while the governance layer catches and escalates the interactions that warrant human attention. Automation where appropriate; human oversight where necessary.


Identity Governance: Every Jeannie Session Is Accountable

Every Jeannie session is anchored to a verifiable identity through nxtlinq's HIT and AIT architecture. When a Berify user initiates a session, a Human Identity Token (HIT) is linked to that session through the authentication layer. When Jeannie is instantiated to handle that session, she receives an AI Identity Token (AIT) scoped specifically to what she is authorized to access and do on behalf of that user.

This means that every action Jeannie takes — every data lookup, every account query, every response generated — is cryptographically attributable to a specific, verified user session. Not a username. Not a cookie. A token-level accountability chain that traces every agent action back to its originating human authorization.


If a question ever arises about what Jeannie did in a specific session — what data she accessed, what she said, what she was asked — nxtlinq's immutable audit ledger provides the complete, tamper-proof record. Not a log that can be cleared. A ledger that cannot be altered.


Why This Architecture Matters Beyond Jeannie

Jeannie is the first production deployment of nxtlinq's governance backend in a client-facing AI concierge context — but the architecture is not bespoke to Berify. Every enterprise deploying a customer-facing AI agent faces the same set of questions:


How do we ensure the agent doesn't expose customer PII to the underlying model?

How do we know what the agent did in any given session, and who authorized it?

How do we scale AI customer service without scaling our compliance and liability exposure at the same rate?

How do we catch high-risk interactions before they become incidents?


nxtlinq's deployment with Berify demonstrates that these questions have answers — and that the answers can be built into the infrastructure layer rather than handled as after-the-fact compliance work. The governance backend ships with the agent. Security is not a post-deployment audit. It is the operating condition.


"The question is not whether your AI agent will encounter sensitive customer data. It will. The question is whether your infrastructure is ready for that moment."

— nxtlinq


What's Next

Jeannie's launch marks the beginning of Berify's agentic AI rollout, with nxtlinq providing the security and governance layer across all AI-enabled customer interactions. As Berify expands Jeannie's capabilities — and as the volume and complexity of customer interactions grows — nxtlinq's infrastructure scales with it.

For organizations watching Berify's deployment and asking whether the same architecture can work for their own client-facing AI agents: it can. The baseline deployment timeline is 14 days, and the governance layer is designed to operate alongside existing identity, authentication, and enterprise application infrastructure without disruption.


nxtlinq is the security and governance backbone for production agentic AI — from client-facing concierge agents like Jeannie to enterprise workflow automation, multi-agent orchestration, and regulated-industry AI deployments.


Learn More

To learn more about how nxtlinq's execution governance platform can power your AI deployment — or to explore a partnership — contact us at the links below.


Recent Posts

See All
Why Are We Still Storing PII in 2026?

The Mercor Breach Is the Wake-Up Call — But Not the First In April 2026, AI startup Mercor—valued at $10B—was hit by a major data breach that exposed candidate profiles, PII, employer data, and even s

 
 
 

Comments


bottom of page