SOPHENTIS

Fail-closed execution boundaries for AI side effects

Only PASS opens the action path. Everything else is denied by default.

Audit-ready receipts you can verify independently — no vendor trust required. Missing or invalid proof → deny.

2-week eval · no install to start · 24h response
Execution Receipt (example) PASS
verdictPASS
actiondeploy:prod/cart-service
principalagent:ci-pipeline
timestamp2026-02-09T14:32:08Z
policy_versionvX.Y.Z
gates_evaluatedN / N passed
evidence_hashsha256:3f8a…c91d
signatureredacted
Independently verifiable · no vendor access required

Every decision produces a receipt. Verify offline. Trust the math.

Fail-closed by default

Missing input, invalid authorization, or uncertainty → deny. An explicit PASS is the only way through.

Offline-verifiable receipts

Cryptographically signed evidence. Audits don't require vendor trust, screenshots, or live services.

Mechanical unreachability

When blocked, the action path doesn't degrade — it ceases to exist. No credentials are ever minted.

Use cases

What gets governed

Built for moments where "oops" is expensive. Any AI-initiated side effect that touches real systems.

deploy

CI/CD and deployments

AI-generated code reaches production only after policy gates pass. No proof, no merge, no deploy.

access

Credential minting

No standing secrets. Short-lived credentials minted only when the verifier proves PASS. Revoked on expiry.

execute

Tool & API execution

Agents calling external APIs, databases, or infrastructure. Every call gated, every outcome receipted.

Mechanics

How it works

A verifier evaluates the proposed action against policy. The verdict determines what happens next.

1

Action proposed

An AI agent requests a side effect — deploy, access, execute.

2

Verifier evaluates

Policy gates check authorization, evidence, and constraints.

3

Verdict returned

One of four outcomes. Only PASS permits execution.

4

Receipt issued

Signed, offline-verifiable proof of the decision and evidence.

PASS FLAG REPAIR BLOCK Only PASS opens the gate. Everything else fails closed.

Built on versioned specifications

Every enforcement behavior maps to a published, versioned spec. Deterministic, auditable, reproducible.

Evidence on deny

Blocked actions still generate receipts. Auditors see what was denied and why — not just what succeeded.

Evaluation partners

See it on your stack

Limited slots. We work with your environment, your policies, your side effects. NDA-friendly.

2 weeks · scoped evaluation No install required to start 24h response time
Contact

Get in touch


Tell us: your environment, what action needs governing, and what "PASS" should mean for you.