AI that earns your trust
Most AI assistants ask you to hand over your data, your credentials, and your control. Sophon was built on the opposite principle: your data lives in infrastructure you run, your secrets stay out of the model’s prompt, and an action above your approval threshold waits for you. The model you choose still sees the prompts you send it.
Your Infrastructure, Your Data
Sophon runs entirely on your servers. Conversations, memory, documents, and credentials never leave your environment, and license validation is offline. There is no usage analytics and no behavioural tracking — the marketplace client checks for updates and reports anonymous install counts, and downloads a package if you turn automatic updates on. All of it stops when you disable the marketplace.
Your data stays in your perimeterYour AI Never Sees Your Secrets
Credentials are stored in an encrypted vault and delivered into the skill's sandbox at call time — never into the model's prompt. The model receives the result of a call, not the API key, OAuth token, or password that made it. A brokered proxy that holds the secret outside the sandbox is on the roadmap, not in the product.
Vaulted, and out of the promptNothing Happens Without Your Say
Every action is classified by risk. Sensitive operations — sending emails, modifying data, executing code — require explicit human approval. Timeout means reject. Sophon never assumes consent.
Human-in-the-loop by defaultSandboxed From the Ground Up
Every skill — bundled, marketplace, or self-authored — runs in a Docker container with CPU, memory, and time limits and no network egress by default. gVisor kernel isolation applies where the runtime is configured, with a process-based fallback when the Docker API is unavailable. Plugins are the exception: they are full-trust local processes, not sandboxed code.
Docker + gVisor where configuredThe posture, stated plainly
Our own assessment, with the mechanism and the tier for each control. Where something is Enterprise-only or has an exception, it says so.
| Control | How it works |
|---|---|
| Data stays on your infrastructure | Self-hosted. Conversations, memory, documents, and credentials never leave your deployment. |
| The model never sees raw credentials | Encrypted vault. The credential is delivered into the skill's sandbox at call time and never into the model's prompt; the model receives the result. The skill itself does hold the credential while it runs. |
| Human approval for sensitive actions | Five risk levels declared per tool; anything at or above your threshold raises a gate, and the shipped default is Medium. Critical always prompts. A timeout or a cancel is never recorded as an approval. |
| Encrypted credential vault | DPAPI-bound on Windows, AES-256 with a local key file elsewhere. Vault, AWS Secrets Manager, and Azure Key Vault on Enterprise. |
| Sandboxed code execution | Docker with CPU, memory, and time limits and no default egress; gVisor where configured. Plugins are excluded — they run full-trust. |
| Outbound connections | A marketplace update check, anonymous install counts, and — only if you opt in to automatic updates — the package download that follows. All stop when the marketplace is disabled. Licensing is offline. |
| SSO / OIDC | Azure AD, Okta, Google Workspace, Auth0 — any OIDC provider. Enterprise tier. |
| Audit logging with export | Immutable trail of every action, user, tool call, and approval. Enterprise tier. |
| Model-agnostic | Anthropic, OpenAI, Gemini, xAI, Mistral, local Ollama and a dozen more provider types, cloud or local. Sophon Gateway ships with no pre-configured provider. |
| Deploy anywhere | Docker Compose or Kubernetes + Helm, on any infrastructure you control. |
Where your credentials go
In most AI systems, the model sees your API keys. In Sophon it never does — the secret goes from the vault into the sandbox running the skill, and only the result comes back.
The AI requests an action → the vault decrypts the credential and hands it to the sandbox running the skill → the skill calls the external API → only the result comes back. The model never sees, logs, or caches credentials, and it is the sandbox — not the model — that holds the secret while the call is in flight.
Where this stops: a compromised skill can read the credential it was given. A broker that keeps the secret outside the sandbox and makes the call on the skill's behalf is on the roadmap. Grant a skill only the connections it needs.
Defense in depth
Six layers of protection working together. Each layer is independently valuable, and each one is documented — including where it stops.
Encrypted Vault
Encrypted at rest — DPAPI-bound to your account on Windows, AES-256 under a local key file on macOS and Linux. Enterprise support for HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault.
OAuth 2.1 + PKCE
All integrations prefer modern OAuth with proof keys. Short-lived tokens, minimum scopes, automatic rotation. Static credentials are a last resort.
Risk Classification Engine
Every tool call is scored from None to Critical. You configure which risk levels auto-approve and which require your review — down to the individual tool. The threshold ships at Medium, and Critical prompts whatever you set it to.
Prompt-Injection Guard
Content that did not come from you is wrapped, scanned, and recorded. Off, Warn, or Block, admin-set for the host and shipping as Warn. Block stops a turn only on third-party content — a tool result, a webhook payload, a message from someone else. It matches known phrasing, so treat it as a tripwire, not a boundary: obfuscated or split instructions get through.
Network Isolation
Sandboxed skills have no network access by default. Skills must explicitly declare network requirements, and elevated access triggers approval gates.
Complete Audit Trail
Every action is logged: who triggered it, what happened, when, and the outcome. Enterprise tier adds compliance export, retention policies, and tamper-evident storage.
A published threat model
Sophon's controls are mapped to MITRE ATLAS — the industry framework for adversarial threats against AI systems — with an open residual-risk roadmap for the gaps we are still closing.
| ATLAS tactic | Example threat | Sophon control |
|---|---|---|
| Execution | Indirect prompt injection | Content wrapping + Warn/Block guard |
| Execution | Malicious skill code | Docker + gVisor sandbox |
| Credential Access | Credential theft | Encrypted vault, out of the prompt |
| Impact | Irreversible action | Human approval gates |
You decide what auto-approves
Every tool call carries a risk level. You configure the threshold — from fully autonomous to fully supervised. It ships at Medium, and the behaviour below is what that default produces.
| Risk Level | Examples | Default Behavior |
|---|---|---|
| None | Search memory, list calendar, read files | Auto-approve |
| Low | Draft email, create reminder, web search | Auto-approve — below the default threshold |
| Medium | Send message, create Jira ticket, execute code | Require review — the default threshold sits here |
| High | Send email, delete data, shell execution | Require review — unless you raise the threshold |
| Critical | Transfer funds, modify security settings | Always prompts — no threshold or override lowers it |
Enterprise compliance ready
Sophon ships the technical controls SOC 2, ISO 27001, HIPAA, and GDPR require. Certification applies to your deployment — Buildersoft holds no attestation of its own.
SSO & Identity
OIDC / SAML integration with any identity provider. Enforce MFA, session policies, and conditional access from your existing IdP.
Role-Based Access Control
Fine-grained RBAC with custom roles. Control who can create agents, install skills, approve actions, access memory, or manage channels.
Multi-Tenant Isolation
Complete data isolation between tenants. Separate databases, memory stores, and credential vaults. No cross-tenant data leakage — by architecture, not policy.
Data Sovereignty
Deploy in any region, on any cloud, or on-premises. Your data residency requirements are met by choosing where to run Sophon — not by trusting a vendor's promise.
Ready to deploy AI you can actually trust?
Read the technical details in our security documentation, or get started with a self-hosted deployment today.