Softnix Gen AI prioritizes data security, access control, and responsible AI usage within enterprise environments. It supports AI Chat, AI Assistant, Knowledge Management, Document Processing, RAG, Webchat, and integrations with internal systems or external communication channels.
This document provides a public-facing overview of Softnix Gen AI security measures for customers and users. It avoids internal technical details, deployment-specific implementation details, and information that could affect system security.
1. Security Overview
Softnix Gen AI is an enterprise AI platform covering AI conversation, content generation, AI assistant management, document processing, knowledge base creation, retrieval-augmented generation, Webchat, and related integrations.
The system is designed in multiple layers, such as user access, API services, AI processing, document and knowledge management, and data storage. This helps limit access boundaries, reduce impact from abnormal events, and support customer data governance policies.
2. Authentication and User Management
Softnix Gen AI supports multiple authentication options depending on the customer's environment, including internal accounts, LDAP or Active Directory integration, and OAuth-based identity provider integration for enterprise single sign-on.
After successful authentication, token-based sessions are used to control access to APIs and platform services. Protected data and functions require token validation before access is allowed.
Internal account passwords are not stored in plaintext and are protected using appropriate one-way cryptographic methods.
3. Access Control
Softnix Gen AI uses Role-Based Access Control, Project-Based Access Control, and Department-Based Access Control to define usage boundaries by role, department, project, or application context.
Administrators can define which user groups can access features such as AI Assistant, Webchat, Knowledge, documents, dashboards, configuration, usage overview, integration keys, and conversation data.
The system supports access scoping by data owner, project, department, application, conversation, and knowledge scope so users can see and manage only authorized information.
4. Data Separation
Softnix Gen AI separates data by usage context, such as user, application owner, project, department, conversation, knowledge base, and document set.
For AI and RAG workflows, the system can bind knowledge, documents, chunks, embeddings, and vector indexes to authorized scopes, reducing the risk of data being mixed across users or departments.
If customers require stronger isolation, such as tenant, network, database, or environment-level separation, this can be designed as part of the customer's deployment architecture.
5. Data Protection
Data exchanged between users and the system should be protected through encrypted HTTPS/TLS connections to reduce the risk of interception or tampering in transit.
Stored data may include user data, application configuration, conversation data, uploaded documents, knowledge data, metadata, usage data, audit logs, and retrieval data used by AI workflows. Storage and encryption policies can be aligned with the actual deployment environment.
For sensitive data such as internal documents, personal data, or data used with AI models, customers should define classification, retention, access, and data processing policies according to organizational requirements.
6. AI and Knowledge Processing Security
Softnix Gen AI supports controlled document and knowledge processing workflows, including document ingestion, chunking, embedding generation, vector index storage, and retrieval for AI responses.
AI Assistant or Webchat can be configured to use only knowledge scopes that are authorized, reducing the risk of retrieving information outside the user's access rights.
Where external AI providers are used, organizations should consider data classification, data residency, and the provider's data processing terms. Private AI or Local LLM deployments can reduce data leaving the customer's environment.
7. Webchat and Integration Security
Softnix Gen AI supports Webchat and integrations while controlling token, application context, conversation context, and data scope related to users or departments.
Connections to external channels or enterprise systems can be scoped by application, department, key, or conversation so each channel accesses only the data and services needed for its purpose.
Customers should define policies for issuing, reviewing, rotating, and revoking API keys or integration credentials according to least privilege and organizational secret management practices.
8. File and Document Security
Softnix Gen AI supports uploading and processing documents for knowledge creation or AI-assisted responses. The system is designed so file storage and metadata can be separated by usage context.
In production, customers should define additional controls according to risk level, such as file size limits, allowed file types, malware scanning, storage access control, and periodic cleanup of unnecessary files.
9. Audit Logging and Traceability
Softnix Gen AI records important system and usage events, such as login, API access, important data changes, permission management, application or conversation usage, and errors needed for investigation.
Audit logs and application logs help administrators review activity, analyze events, troubleshoot issues, and support security governance processes.
In production, customers should define log retention, log redaction, centralized logging, alerting, and audit trail protection policies according to their requirements and applicable standards.
10. Infrastructure Security
Softnix Gen AI supports deployment in controlled environments such as cloud, private cloud, on-premise, containerized deployment, or networks with restricted external connectivity.
The system can be placed behind a reverse proxy, ingress controller, or API gateway for TLS, request policy, CORS, rate limiting, network boundary, and internal service access control.
Databases, object storage, vector stores, message services, or related internal components should be restricted to private networks and exposed only to authorized services.
11. Secret and Configuration Management
Secrets such as token signing secrets, database credentials, integration keys, provider API keys, and application secrets should be stored through environment configuration, a secret manager, or the deployment platform's secret management mechanism.
Secrets should not be exposed through logs, error responses, screenshots, or public documentation. Credential rotation procedures should be defined according to security policy or risk events.
12. Backup and Recovery
Softnix Gen AI can define backup and recovery policies covering metadata, conversations, configuration, uploaded files, knowledge content, vector indexes, logs, and deployment configuration.
For production, customers should define RPO/RTO according to SLA requirements, enable automated backups, encrypt backups, restrict backup access, and test recovery periodically.
13. Deployment Options
Softnix Gen AI supports multiple deployment options based on customer security and operational requirements, such as:
- Cloud or managed infrastructure
- Customer private cloud
- On-premise deployment
- Private AI or Local LLM deployment
- Deployment in environments with controlled external connectivity
- Deployment in environments requiring high network isolation
14. Continuous Security Improvement
Softnix continuously improves security controls across access control, secret management, data protection, usage monitoring, AI provider integration controls, environment hardening, and security testing within the development lifecycle.
15. Security Reporting
If customers identify a security concern, they may contact the system administrator or Softnix support team so the issue can be reviewed and handled through the appropriate process.
