SoxAI
For Enterprises

AI without the data exposure incident

Your data scientists need access to GPT-4o, Claude, and Gemini. Your CISO needs zero credit-card numbers leaking into prompts. SoxAI sits in the middle and makes both possible — DLP-scanned, encrypted at rest, audit-logged end-to-end.

Self-hosted optionSource-availableNo data sent for scanning
Procurement at-a-glance
  • DLP scans every request before it leaves the perimeter
  • AES-256-GCM at rest, TLS 1.3 in transit
  • Immutable audit trail with forced logging on decrypt
  • Application-layer tenant isolation (PG RLS as defence-in-depth)
  • Self-hosted deployment with full source code access
  • SLA + 24/7 dedicated support
SECURITY HEADLINE

DLP for AI traffic, built into the gateway

Same surface as OpenAI's API. Scanning, encryption, and audit baked into every request — not a separate sidecar.

DLP-protected requests

Every request scanned against 15 builtin detectors (credit cards, API keys, PII, private keys, internal IPs, etc.) plus your tenant-private regex/dictionary patterns. Mask, block, or audit per policy.

Prompt injection guard

Every request scanned for prompt injection, jailbreak, role-confusion, encoding evasion, and tool-hijack patterns. 195+ builtin patterns across 9 languages. Block, sanitize, or audit per policy. Fail-open by design — never trades availability for security theater.

Encryption at rest

Matched plaintext + context encrypted with AES-256-GCM before persisting. HMAC SHA-256 fingerprint for hash-only deduplication. Multi-key registry for zero-downtime rotation.

Audit-before-plaintext

Decrypting any DLP finding writes to audit_logs BEFORE plaintext returns. If audit insert fails, the operation aborts with no plaintext exposed. There is no path that bypasses the trail.

Immutable audit log

Trigger blocks DELETE/UPDATE on audit_logs at the database level. Every sensitive operation lands here append-only — exportable as compliance evidence, retention enforced at your infra layer.

Access controls your IT team will sign off on

IdP-driven SSO, hardware-key step-up, multi-tenant isolation, self-hosted option. Procurement-ready.

OIDC SSO + 2FA

Connect Okta / Azure AD / Auth0 / Google Workspace. WebAuthn step-up for sensitive operations (decrypt, delete, role change). No passwords for IT to rotate, no shared seats.

Multi-tenant isolation

Application-layer tenant_id scoping on every sqlc query, with PostgreSQL Row-Level Security as defence-in-depth. Cross-tenant probes return 404 (uniform with non-existent IDs) — no enumeration vector. Per-tenant DLP policies, quotas, price tables.

Self-hosted option

Source-available commercial license. Deploy on your own Kubernetes, your own PostgreSQL, your own Redis. Same gateway, same admin console, same DLP engine — running entirely inside your perimeter. License Engine ensures supported version + entitlement signing.

24/7 dedicated support

Direct Slack channel with our engineering team. SLA-backed incident response. Quarterly compliance review session. Custom SAML / SCIM provisioning available on request.

Tenant isolation — defence in depth

Application-layer tenant_id scoping on every sqlc query; PostgreSQL Row-Level Security as a backstop. Cross-tenant probes return 404 — no enumeration vector.

Tenant Auser A1, A2…Tenant Buser B1, B2…Tenant Cuser C1, C2…Layer 1: Apptenant_id in everysqlc queryWHERE tenant_id = $1Cross-tenant probes →uniform 404 (not 403)No enumeration vectorif app skipsLayer 2: PG RLSdefence-in-depthpolicy on selected tablesCREATE POLICY tenant_isosession-var scopedvia app.tenant_idblocks runtime driftPostgreSQLrow-level data404 on cross-tenant probe
Every sqlc query carries tenant_id; PostgreSQL RLS provides backstop policy enforcement

DLP policies, per tenant

Each customer tenant configures its own detectors, policies, and bindings. Platform admins see the audit trail; they don't see the customer's prompts.

console.soxai.io / dlp / policies
DLP policy creation dialog with detectors selected, action set to mask, confidence threshold configured
DLP policy creation · detector multi-select · action / confidence / path-excludes / priority

Prompt Guard policies, per tenant

Each tenant configures its own threat-category enablement, custom patterns, sanitize modes, and optional LLM-judge channel with a daily call budget. Platform operators see the audit trail; they never see the customer's prompts.

Request bodyOpenAI-compatibleData Loss Preventionprotects against accidental exfiltrationDefends againstAccidental data leakageTypical sourceYour own application codeFailure modeFail-closedActionsmask · block · audit_onlyPipeline positionRuns firstPrompt Guardprotects against adversarial inputsDefends againstAdversarial instruction injectionTypical sourceExternal user / fetched contentFailure modeFail-openActionsblock · sanitize · auditPipeline positionRuns secondUpstream modelOpenAI / Anthropic / …
Same gateway hop, different threat models, opposite failure modes. Both run on every request before the upstream provider sees a byte.

Compliance checklist

Hand this to your security team.

Data Loss Prevention
15 builtin detectors + custom regex/dictionary, mask/block/audit policies
Prompt injection defense
195+ builtin patterns (9 languages), 7 threat categories, three-layer detection, optional LLM judge with daily budget cap
Encryption at rest
AES-256-GCM with multi-key rotation registry
Encryption in transit
TLS 1.3 (Cloudflare-terminated or your own ingress)
Password storage
Argon2id
Access tokens
SHA-256-hashed in DB, IP allowlist + country check
Authentication
OIDC SSO + OAuth + WebAuthn step-up
Multi-tenancy
Application-layer tenant_id scoping; PostgreSQL RLS as defence-in-depth
Audit trail
Immutable, append-only audit_logs (DB trigger blocks DELETE/UPDATE)
Forced audit on decrypt
audit-before-plaintext invariant, system_admin only
Deployment
SaaS or self-hosted (source-available commercial license)
Source code access
Commercial license includes full source for self-host

Talk to our team

We'll spin up a sandbox tenant with DLP, audit, and SSO configured against your IdP. 30 minutes, no slides — just a console you can break.