check this thread:
http://forum.sun.com/jive/thread.jspa?threadID=98971&messageID=341351#34135 1
There are some clues in the SIpkgtls package I mentioned -- it's perl-based, so you could use their strategy for encapsulating the sftp daemon in a chrooted env with a combination of lofiadm and chroot.
Don't have the cycles to think of details how, but I'll try and spend some time over the weekend thinking about it.