Today, Shofield AI is marking two connected milestones. Founder Richy Shofield has completed OpenAI’s identity-verification process and his Daybreak access is active. At the same time, we are officially opening Shofield AI Cyber Security in controlled preview: an independent module for governed, evidence-led defensive workflows inside the Shofield AI Platform.
The access milestone and the product launch should not be conflated. Daybreak is OpenAI’s governed cyber-defence environment for approved users. Shofield AI Cyber Security is our product, built and operated independently. We are celebrating both while being exact about what each one permits.
What active Daybreak access means—and what it does not
OpenAI describes Daybreak as a governed cyber-defence stack that combines specialised models, defensive tools and workflows. Its public operating loop focuses on inventory, discovery, dynamic validation, ownership assignment and verified remediation. The purpose is not unlimited capability. It is to help legitimate defenders move from a possible issue to an owned, validated and repaired one.
Richy’s approved access supports authorised cybersecurity work inside the scope OpenAI has granted. That means work on systems Shofield owns or is explicitly authorised to assess. It remains tied to the approved identity, workspace or project, model and product surface. It cannot simply be passed through to customers or embedded into an external product without separate approval.
The verification screen does not establish OpenAI partnership, certification or endorsement. It does not prove access to the separately controlled Daybreak Red or GPT-5.6 Cyber model, and it does not establish zero-data-retention terms. We will not claim any of those things without the corresponding written approval.
A vulnerability is not resolved until the loop closes.
Daybreak’s public framework treats defensive work as a controlled operating loop rather than a one-off scan.
Owned or explicitly authorised systems · Approved identity and surface · Human accountability
- 01Inventory
Establish the assets and exposure surface.
→ - 02Discover
Identify supported signals and possible weaknesses.
→ - 03Validate
Test whether the issue is real and consequential.
→ - 04Assign
Attach an accountable owner and decision route.
→ - 05Remediate
Fix, re-test and retain proof of closure.
Architecture takeawayFaster discovery has value only when validation, ownership and verified remediation keep pace.
What the Shofield AI Cyber Security Engine can do today
The first release is a controlled preview, not a generic promise to secure everything. A signed-in user can open the module and review its operating model. The repository workflow is built and validated in tests, but production GitHub App activation and one end-to-end authorised repository scan are still required. Until then, repository scanning is not generally available.
The prepared assessment workflow combines deterministic checks with governed AI analysis of selected security-relevant source files. Its findings model records severity, confidence, category, affected file and location, technical evidence, business impact and recommended remediation. Records are designed to remain workspace-bounded, while repeated findings are deduplicated so the queue reflects current work rather than noise.
From a finding, the workflow can prepare a proposed fix for human review. It is designed not to silently modify production. Verification checks the current file against the original evidence before closure. Decisions such as awaiting approval, fix in progress, resolved or accepted risk remain visible in the audit trail.
Live capability, required authority and explicit limits.
The module is useful because it makes the operating boundary visible rather than hiding it behind an AI result.
| Operating dimension | Controlled previewCurrent release | Human / contractual gateRequired control | Not claimedOutside launch scope |
|---|---|---|---|
| Assessment | Browsable module; repository connection prepared | Production App activation and authorised scan | Unbounded penetration testing |
| Findings | Evidence, severity, confidence and impact | Human validation and prioritisation | Proof that software is secure |
| Remediation | Proposed fixes and current-file verification | Approval before implementation | Autonomous production changes |
| Operations | Workspace audit trail and AI Employee controls | Named owners and escalation route | 24/7 SOC, MDR or guaranteed response |
| Daybreak | Approved internal defensive access | OpenAI’s exact identity and surface limits | Partnership or customer-facing access |
Governance takeawayThe preview is production-minded precisely because readiness, authority and exclusions are as visible as capability.
Designed for authorised defence, not security theatre
Before any assessment begins, the system owner, assets, repositories, permitted methods, data handling, escalation contacts and approval authority must be explicit. Daybreak access does not replace a statement of work or rules of engagement. Neither does a connection button. Technical capability is not permission.
The module does not turn Shofield AI into a 24/7 security operations centre, managed detection and response provider, emergency incident-response firm or certification body. Penetration testing, live exploitation, production patching, formal assurance and specialist response remain separately scoped work requiring qualified capacity and the right contracts.
The first problem to solve is AI exposure
For many organisations, the most urgent risk is not an exotic attack. It is losing track of which models, copilots, agents, integrations and employee accounts can reach sensitive information or take action. Permissions were often designed for human-operated applications, then inherited by AI tools with broader search, synthesis and execution capacity.
That is why our commercial entry point is a 30-day Secure AI Exposure Assessment. We start with one important workflow and map the models, vendors, identities, permissions, data flows, secrets, integrations, tools and audit evidence around it. The output is not a generic risk report. It is an owned control architecture and a 90-day remediation route.
Our first launch cohort prioritises multi-office accounting, audit and advisory firms already using Copilot, ChatGPT or embedded AI. These organisations hold sensitive client information, carry professional accountability and often need to govern adoption without stopping useful experimentation. The Managing Partner, IT owner and Quality or Compliance leader need one shared view of the exposure and the decision.
One workflow. One authorised boundary. One decision route.
The assessment converts fragmented AI-security concerns into a funded and accountable implementation decision.
No work before written authority · No production change without approval · No unsupported assurance claim
- 01Authorise
Agree assets, owners, methods, exclusions and escalation.
→ - 02Map
Inventory AI, systems, identities, permissions and data paths.
→ - 03Prioritise
Validate evidence and rank risk by business consequence.
→ - 04Design
Define approvals, logging, rollback and target controls.
→ - 05Decide
Deliver the 90-day roadmap and go / no-go decision.
Architecture takeawayThe goal is not another cyber report. It is a defensible decision about what to fix, who owns it and what moves into production next.
The limited launch cohort is open
We are inviting a small number of qualified organisations to begin with one high-priority, explicitly authorised workflow or repository. Scope, specialist requirements, commercial terms and delivery capacity will be confirmed before commitment. That protects the client, the systems being assessed and the integrity of the work.
