SoxAIDocs
Security

Security Overview

How SoxAI protects your data, credentials, and API access

Security

SoxAI is designed with security as a core requirement, not an afterthought. This section covers the security architecture, authentication mechanisms, and controls available to you.

Summary

AreaApproach
API Key StorageAES-256-GCM encryption at rest
Password HashingArgon2id
Token AuthenticationRS256 JWT (15-minute access tokens)
MFAWebAuthn (hardware keys, passkeys)
TransportTLS 1.2+ enforced; HTTP rejected
Database IsolationPostgreSQL Row-Level Security per tenant
SQL InjectionParameterized queries via sqlc (no string concatenation)
SSRF PreventionURL allowlist validation before any upstream request
Error SanitizationInternal errors stripped before client delivery
Data Loss PreventionRegex + dictionary scan on every request; mask, block, or audit_only sensitive content
Prompt GuardThree-layer injection and jailbreak detection; block, sanitize, or audit adversarial prompts

Authentication

SoxAI supports three authentication methods:

Email + Password Standard email/password login with Argon2id password hashing. Login failures are rate-limited (5 failures → 15-minute lockout).

OAuth (Google, GitHub) Sign in with your Google or GitHub account. OAuth tokens are not stored; only the user identity is persisted.

WebAuthn (Passkeys, Hardware Keys) Phishing-resistant authentication using the WebAuthn standard. Supports USB security keys (YubiKey), platform authenticators (Face ID, Windows Hello), and passkeys synced via iCloud or Google Password Manager.

API Token Security

API tokens are:

  • Prefixed with sox- for easy detection in secret scanning
  • Never stored in plaintext — only a secure hash is stored in the database
  • Scoped to a single tenant
  • Revocable immediately from the Console

If you suspect a token has been compromised:

  1. Go to Console → Settings → API Tokens
  2. Find the token and click Revoke
  3. Create a new token
  4. Update your application

Session Tokens

Web sessions use short-lived JWTs:

TokenLifetimeStorage
Access Token15 minutesMemory only (not localStorage)
Refresh Token7 daysHttpOnly, Secure, SameSite=Strict cookie

Refresh tokens are rotated on each use. Concurrent use of a refresh token (possible after theft) triggers revocation of the entire session family.

Rate Limiting and Brute Force Protection

  • Login: max 5 failures per account per 15 minutes
  • API requests: rate limited per token (see Rate Limits)
  • Password reset: max 3 requests per email per hour

Vulnerability Disclosure

To report a security vulnerability, email [email protected]. Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact

We aim to acknowledge reports within 24 hours and provide a fix timeline within 72 hours for critical issues.

More Information