Security Overview
How SoxAI protects your data, credentials, and API access
Security
SoxAI is designed with security as a core requirement, not an afterthought. This section covers the security architecture, authentication mechanisms, and controls available to you.
Summary
| Area | Approach |
|---|---|
| API Key Storage | AES-256-GCM encryption at rest |
| Password Hashing | Argon2id |
| Token Authentication | RS256 JWT (15-minute access tokens) |
| MFA | WebAuthn (hardware keys, passkeys) |
| Transport | TLS 1.2+ enforced; HTTP rejected |
| Database Isolation | PostgreSQL Row-Level Security per tenant |
| SQL Injection | Parameterized queries via sqlc (no string concatenation) |
| SSRF Prevention | URL allowlist validation before any upstream request |
| Error Sanitization | Internal errors stripped before client delivery |
| Data Loss Prevention | Regex + dictionary scan on every request; mask, block, or audit_only sensitive content |
| Prompt Guard | Three-layer injection and jailbreak detection; block, sanitize, or audit adversarial prompts |
Authentication
SoxAI supports three authentication methods:
Email + Password Standard email/password login with Argon2id password hashing. Login failures are rate-limited (5 failures → 15-minute lockout).
OAuth (Google, GitHub) Sign in with your Google or GitHub account. OAuth tokens are not stored; only the user identity is persisted.
WebAuthn (Passkeys, Hardware Keys) Phishing-resistant authentication using the WebAuthn standard. Supports USB security keys (YubiKey), platform authenticators (Face ID, Windows Hello), and passkeys synced via iCloud or Google Password Manager.
API Token Security
API tokens are:
- Prefixed with
sox-for easy detection in secret scanning - Never stored in plaintext — only a secure hash is stored in the database
- Scoped to a single tenant
- Revocable immediately from the Console
If you suspect a token has been compromised:
- Go to Console → Settings → API Tokens
- Find the token and click Revoke
- Create a new token
- Update your application
Session Tokens
Web sessions use short-lived JWTs:
| Token | Lifetime | Storage |
|---|---|---|
| Access Token | 15 minutes | Memory only (not localStorage) |
| Refresh Token | 7 days | HttpOnly, Secure, SameSite=Strict cookie |
Refresh tokens are rotated on each use. Concurrent use of a refresh token (possible after theft) triggers revocation of the entire session family.
Rate Limiting and Brute Force Protection
- Login: max 5 failures per account per 15 minutes
- API requests: rate limited per token (see Rate Limits)
- Password reset: max 3 requests per email per hour
Vulnerability Disclosure
To report a security vulnerability, email [email protected]. Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
We aim to acknowledge reports within 24 hours and provide a fix timeline within 72 hours for critical issues.
More Information
- Data Privacy — What data we collect and how it is used
- Compliance — Regulatory compliance and certifications
- Data Loss Prevention — Scan and redact sensitive content in AI requests
- Prompt Guard — Detect and block prompt injection attacks