Post-Activation Network Lockdown

Sophia NLU is designed for privacy, and has no functional need for an internet connection. If you wish to enforce this at the OS level, we recommend the Network Namespace approach.

The Namespace Approach (Recommended)

This is the cleanest method. It creates a virtual “sandbox” where the only available network interface is the local loopback (127.0.0.1).

1. Create the Isolated Namespace

sudo ip netns add nlu-isolated
sudo ip netns exec nlu-isolated ip link set lo up

2. Run Sophia within the Sandbox

sudo ip netns exec nlu-isolated /path/to/your/sophia_binary

Other Methods

Systemd Sandboxing

If you are using the systemd method from the Advanced Guide, you can add these lines to your [Service] section to use built-in Linux kernel isolation:

[Service]
# ... other settings ...
IPAddressAllow=localhost
IPAddressDeny=any

Firewall (nftables)

To block all external traffic for the binary specifically:

sudo nft add rule inet filter output meta comm "sophia_nlu" drop

By using these methods, you ensure that Sophia remains a powerful, local-only utility that respects your “Privacy-First” ethos.