Sophon 2.0 is here
Security-first architecture

AI that earns your trust

Most AI assistants ask you to hand over your data, your credentials, and your control. Sophon was built on the opposite principle: your data lives in infrastructure you run, your secrets stay out of the model’s prompt, and an action above your approval threshold waits for you. The model you choose still sees the prompts you send it.

Your Infrastructure, Your Data

Sophon runs entirely on your servers. Conversations, memory, documents, and credentials never leave your environment, and license validation is offline. There is no usage analytics and no behavioural tracking — the marketplace client checks for updates and reports anonymous install counts, and downloads a package if you turn automatic updates on. All of it stops when you disable the marketplace.

Your data stays in your perimeter

Your AI Never Sees Your Secrets

Credentials are stored in an encrypted vault and delivered into the skill's sandbox at call time — never into the model's prompt. The model receives the result of a call, not the API key, OAuth token, or password that made it. A brokered proxy that holds the secret outside the sandbox is on the roadmap, not in the product.

Vaulted, and out of the prompt

Nothing Happens Without Your Say

Every action is classified by risk. Sensitive operations — sending emails, modifying data, executing code — require explicit human approval. Timeout means reject. Sophon never assumes consent.

Human-in-the-loop by default

Sandboxed From the Ground Up

Every skill — bundled, marketplace, or self-authored — runs in a Docker container with CPU, memory, and time limits and no network egress by default. gVisor kernel isolation applies where the runtime is configured, with a process-based fallback when the Docker API is unavailable. Plugins are the exception: they are full-trust local processes, not sandboxed code.

Docker + gVisor where configured

The posture, stated plainly

Our own assessment, with the mechanism and the tier for each control. Where something is Enterprise-only or has an exception, it says so.

ControlHow it works
Data stays on your infrastructureSelf-hosted. Conversations, memory, documents, and credentials never leave your deployment.
The model never sees raw credentialsEncrypted vault. The credential is delivered into the skill's sandbox at call time and never into the model's prompt; the model receives the result. The skill itself does hold the credential while it runs.
Human approval for sensitive actionsFive risk levels declared per tool; anything at or above your threshold raises a gate, and the shipped default is Medium. Critical always prompts. A timeout or a cancel is never recorded as an approval.
Encrypted credential vaultDPAPI-bound on Windows, AES-256 with a local key file elsewhere. Vault, AWS Secrets Manager, and Azure Key Vault on Enterprise.
Sandboxed code executionDocker with CPU, memory, and time limits and no default egress; gVisor where configured. Plugins are excluded — they run full-trust.
Outbound connectionsA marketplace update check, anonymous install counts, and — only if you opt in to automatic updates — the package download that follows. All stop when the marketplace is disabled. Licensing is offline.
SSO / OIDCAzure AD, Okta, Google Workspace, Auth0 — any OIDC provider. Enterprise tier.
Audit logging with exportImmutable trail of every action, user, tool call, and approval. Enterprise tier.
Model-agnosticAnthropic, OpenAI, Gemini, xAI, Mistral, local Ollama and a dozen more provider types, cloud or local. Sophon Gateway ships with no pre-configured provider.
Deploy anywhereDocker Compose or Kubernetes + Helm, on any infrastructure you control.

Where your credentials go

In most AI systems, the model sees your API keys. In Sophon it never does — the secret goes from the vault into the sandbox running the skill, and only the result comes back.

AI AgentSees results only
The prompt boundaryNo secret crosses it
Encrypted VaultEncrypted at rest
Sandboxed SkillCalls the API

The AI requests an action → the vault decrypts the credential and hands it to the sandbox running the skill → the skill calls the external API → only the result comes back. The model never sees, logs, or caches credentials, and it is the sandbox — not the model — that holds the secret while the call is in flight.

Where this stops: a compromised skill can read the credential it was given. A broker that keeps the secret outside the sandbox and makes the call on the skill's behalf is on the roadmap. Grant a skill only the connections it needs.

Defense in depth

Six layers of protection working together. Each layer is independently valuable, and each one is documented — including where it stops.

Encrypted Vault

Encrypted at rest — DPAPI-bound to your account on Windows, AES-256 under a local key file on macOS and Linux. Enterprise support for HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault.

OAuth 2.1 + PKCE

All integrations prefer modern OAuth with proof keys. Short-lived tokens, minimum scopes, automatic rotation. Static credentials are a last resort.

Risk Classification Engine

Every tool call is scored from None to Critical. You configure which risk levels auto-approve and which require your review — down to the individual tool. The threshold ships at Medium, and Critical prompts whatever you set it to.

Prompt-Injection Guard

Content that did not come from you is wrapped, scanned, and recorded. Off, Warn, or Block, admin-set for the host and shipping as Warn. Block stops a turn only on third-party content — a tool result, a webhook payload, a message from someone else. It matches known phrasing, so treat it as a tripwire, not a boundary: obfuscated or split instructions get through.

Network Isolation

Sandboxed skills have no network access by default. Skills must explicitly declare network requirements, and elevated access triggers approval gates.

Complete Audit Trail

Every action is logged: who triggered it, what happened, when, and the outcome. Enterprise tier adds compliance export, retention policies, and tamper-evident storage.

Mapped to MITRE ATLAS

A published threat model

Sophon's controls are mapped to MITRE ATLAS — the industry framework for adversarial threats against AI systems — with an open residual-risk roadmap for the gaps we are still closing.

15
ATLAS tactics covered
34
Techniques mapped
10
Trust boundaries
ATLAS tacticExample threatSophon control
ExecutionIndirect prompt injectionContent wrapping + Warn/Block guard
ExecutionMalicious skill codeDocker + gVisor sandbox
Credential AccessCredential theftEncrypted vault, out of the prompt
ImpactIrreversible actionHuman approval gates

You decide what auto-approves

Every tool call carries a risk level. You configure the threshold — from fully autonomous to fully supervised. It ships at Medium, and the behaviour below is what that default produces.

Risk LevelExamplesDefault Behavior
NoneSearch memory, list calendar, read filesAuto-approve
LowDraft email, create reminder, web searchAuto-approve — below the default threshold
MediumSend message, create Jira ticket, execute codeRequire review — the default threshold sits here
HighSend email, delete data, shell executionRequire review — unless you raise the threshold
CriticalTransfer funds, modify security settingsAlways prompts — no threshold or override lowers it

Enterprise compliance ready

Sophon ships the technical controls SOC 2, ISO 27001, HIPAA, and GDPR require. Certification applies to your deployment — Buildersoft holds no attestation of its own.

SSO & Identity

OIDC / SAML integration with any identity provider. Enforce MFA, session policies, and conditional access from your existing IdP.

Role-Based Access Control

Fine-grained RBAC with custom roles. Control who can create agents, install skills, approve actions, access memory, or manage channels.

Multi-Tenant Isolation

Complete data isolation between tenants. Separate databases, memory stores, and credential vaults. No cross-tenant data leakage — by architecture, not policy.

Data Sovereignty

Deploy in any region, on any cloud, or on-premises. Your data residency requirements are met by choosing where to run Sophon — not by trusting a vendor's promise.

Ready to deploy AI you can actually trust?

Read the technical details in our security documentation, or get started with a self-hosted deployment today.