Trust centre

Security is a boundary you can inspect.

Sourceform is built so authorization, source provenance, and delivery evidence remain visible. This page separates controls that exist today from assurance work still required before general availability.

Data boundaryEU-region architecture

Production infrastructure is designed for EU regions. Live hosting and subprocessor evidence will be published before GA.

Model useNo customer-data training

Product policy prohibits using tenant content to train Sourceform or provider models.

RuntimeNo open internet or tools

Answer generation is restricted to authorized evidence and fails closed when dependencies cannot verify a response.

Control evidence

What the product enforces.

These are implementation claims, not substitutes for a customer’s own legal assessment or a third-party certification.

01
Tenant isolation

Tenant scope comes from authenticated identity and membership. Client-supplied tenant identifiers are never trusted.

Default-deny authorization and tenant-scoped persistence
Implemented
02
Evidence-preserving answers

Retrieval results retain original evidence and are reauthorized before any model egress.

Exact source versions, locators, and immutable deployments
Implemented
03
Fail-closed delivery

Provider or verifier failure produces no uncited answer. Abstentions and failures are not billed as verified answers.

Explicit answer outcomes and verifier publication gates
Implemented
04
Audited operations

Sensitive support and platform operations require an authenticated actor and create evidence for review.

Trace IDs, immutable release references, and operation records
Implemented
Data lifecycle

Retention is selected. Deletion is tracked.

Conversation content can be retained for 0, 30, or 90 days. Export and deletion are explicit account operations; deletion is designed to propagate across primary storage, object storage, indexes, semantic data, graph data, and cache.

  1. 01Collect minimallyOnly content needed for an answer or consented handoff.
  2. 02Retain deliberately0, 30, or 90 day conversation-content settings.
  3. 03Delete with evidenceTracked propagation rather than a silent UI disappearance.
Open release gates

What we will not overclaim.

Required before GAIndependent penetration test

Scope, remediation evidence, and retest must be complete.

Required before GAExternal legal validation

GDPR and AI Act positioning, contracts, and notices require qualified counsel review.

Not claimedFormal certifications

Sourceform does not currently claim ISO 27001, SOC 2, or other third-party certification.

Need the detail?

Start with the architecture and the limits.

Read documentation Contact security