Tests passed
Evidence generated per run
Typecheck, lint, test, audit, build, and readiness commands are recorded in Phase 14.
Free IDE extension for risk-free vibe coding — keep secrets out of AI.
SoterAI protects company data and AI-agent actions before sensitive context reaches external AI systems. This page documents what we test, how we handle data, the controls we run, how you can deploy us, and how to report a vulnerability.
We do not claim complete protection or certification. Customers remain responsible for secure design, access control, monitoring, incident response, and human oversight.
soterai · security posture
OPERATIONALSelf-authored regression and adversarial coverage. Independent third-party auditing is recommended and welcomed.
Public benchmark
Self-maintained synthetic dataset with public methodology
Latest benchmark run
0.00% false-positive rate on 1,000 synthetic benign controls
Unit + integration suites
Guard, agent-firewall, auth, billing, retention
E2E guard scenarios
Real attack flows against a live build
Full benchmark data: /benchmark · live system status: /status
Tests passed
Evidence generated per run
Typecheck, lint, test, audit, build, and readiness commands are recorded in Phase 14.
Benchmark page
Published methodology
Self-maintained synthetic benchmark; not an independent third-party study.
Marketplace status
Status-labeled
No marketplace approval is claimed unless a live listing or approval record exists.
Security methodology
Documented
Internal self-pentest and disclosure process are tracked separately from external audit evidence.
External pentest
EVIDENCE REQUIRED
Enterprise GA claims remain blocked until an independent report exists.
SOC2: readiness in progress. Pentest: EVIDENCE REQUIRED unless a signed external report is added. Security contact: [email protected].
See also our privacy policy, subprocessors, and data retention.
Layered rules for prompt injection, jailbreaks, encoding/obfuscation, multilingual bypass, PII, secrets, and unsafe output.
HSTS in production, strict Content-Security-Policy, X-Frame-Options DENY, nosniff, and a locked-down Permissions-Policy.
Session-based auth with CSRF protection; per-project API keys are stored only as hashes, never in plaintext.
HMAC-signed JSONL/CSV exports so downstream SIEM and compliance pipelines can verify integrity.
Tool-call authorization, agent passports, approvals, and escrow for autonomous workflows before risky actions execute.
Secrets live in environment configuration (gitignored); the repo is scanned to keep keys and tokens out of source control.
Control details and posture: /security · /compliance/owasp-llm-top-10
Hosted guard APIs, dashboard, and audit storage. Fastest path to production.
Run the full stack in your own VPC for data residency and isolation requirements.
Inline SDK detection at the edge with centralized policy, reporting, and audit.
Report suspected vulnerabilities to the security contact listed in your enterprise agreement or deployment runbook. Include affected URLs, impact, reproduction steps, and whether any data was accessed. Only test systems you own or are authorized to assess — do not access, modify, delete, or exfiltrate data that is not yours.
Read the full disclosure policyTry the live playground, review the benchmark, or talk to us about self-hosting.