Production infrastructure is designed for EU regions. Live hosting and subprocessor evidence will be published before GA.
Security is a boundary you can inspect.
Sourceform is built so authorization, source provenance, and delivery evidence remain visible. This page separates controls that exist today from assurance work still required before general availability.
Product policy prohibits using tenant content to train Sourceform or provider models.
Answer generation is restricted to authorized evidence and fails closed when dependencies cannot verify a response.
What the product enforces.
These are implementation claims, not substitutes for a customer’s own legal assessment or a third-party certification.
Tenant scope comes from authenticated identity and membership. Client-supplied tenant identifiers are never trusted.
Default-deny authorization and tenant-scoped persistenceRetrieval results retain original evidence and are reauthorized before any model egress.
Exact source versions, locators, and immutable deploymentsProvider or verifier failure produces no uncited answer. Abstentions and failures are not billed as verified answers.
Explicit answer outcomes and verifier publication gatesSensitive support and platform operations require an authenticated actor and create evidence for review.
Trace IDs, immutable release references, and operation recordsRetention is selected. Deletion is tracked.
Conversation content can be retained for 0, 30, or 90 days. Export and deletion are explicit account operations; deletion is designed to propagate across primary storage, object storage, indexes, semantic data, graph data, and cache.
- 01Collect minimallyOnly content needed for an answer or consented handoff.
- 02Retain deliberately0, 30, or 90 day conversation-content settings.
- 03Delete with evidenceTracked propagation rather than a silent UI disappearance.
What we will not overclaim.
Scope, remediation evidence, and retest must be complete.
GDPR and AI Act positioning, contracts, and notices require qualified counsel review.
Sourceform does not currently claim ISO 27001, SOC 2, or other third-party certification.