Sophia NLU is designed for privacy, and has no functional need for an internet connection. If you wish to enforce this at the OS level, we recommend the Network Namespace approach.
The Namespace Approach (Recommended)
This is the cleanest method. It creates a virtual “sandbox” where the only available network interface is the local loopback (127.0.0.1).
1. Create the Isolated Namespace
sudo ip netns add nlu-isolated
sudo ip netns exec nlu-isolated ip link set lo up
2. Run Sophia within the Sandbox
sudo ip netns exec nlu-isolated /path/to/your/sophia_binary
Other Methods
Systemd Sandboxing
If you are using the systemd method from the Advanced Guide, you can add these lines to your [Service] section to use built-in Linux kernel isolation:
[Service]
# ... other settings ...
IPAddressAllow=localhost
IPAddressDeny=any
Firewall (nftables)
To block all external traffic for the binary specifically:
sudo nft add rule inet filter output meta comm "sophia_nlu" drop
By using these methods, you ensure that Sophia remains a powerful, local-only utility that respects your “Privacy-First” ethos.