Trust centre

Security is a boundary you can inspect.

Sourceform is built so authorization, source provenance, and delivery evidence remain visible. This page separates controls implemented in the repository from deployment and assurance work still required before general availability.

Data boundaryEU infrastructure, explicit model boundary

Production infrastructure is designed for EU regions. Model processing is EU by default; an approved Global model route is labelled explicitly and bound to one immutable release. Live hosting and subprocessor evidence will be published before GA.

Model useNo customer-data training

Product policy prohibits using tenant content to train Sourceform or provider models.

RuntimeNo model tools; bounded provider routes

The Answer Runtime sends only authorized evidence and exposes no tools. The private gateway uses code-owned HTTPS provider origins; network-level egress proof remains an open live gate.

Control evidence

What the product enforces.

These controls are implemented and tested in repository code. They are not described as live production controls until the signed staging and production deployment gates pass, and they are not substitutes for legal assessment or certification.

01
Tenant isolation

Tenant scope comes from authenticated identity and membership. Client-supplied tenant identifiers are never trusted.

Default-deny authorization and tenant-scoped persistence
Implemented in code · live gate open
02
Evidence-preserving answers

Retrieval results retain original evidence and are reauthorized before any model egress.

Exact source versions, locators, and immutable deployments
Implemented in code · live gate open
03
Fail-closed delivery

Provider or verifier failure produces no uncited answer. Abstentions and failures are not billed as verified answers.

Explicit answer outcomes and verifier publication gates
Implemented in code · live gate open
04
Audited operations

Sensitive support and platform operations require an authenticated actor and create evidence for review.

Trace IDs, immutable release references, and operation records
Implemented in code · live gate open
Data lifecycle

Retention is selected. Deletion is tracked.

Conversation content can be retained for 0, 30, or 90 days. Export and deletion are explicit account operations; deletion is designed to propagate across primary storage, object storage, indexes, semantic data, graph data, and cache.

  1. 01Collect minimallyOnly content needed for an answer or consented handoff.
  2. 02Retain deliberately0, 30, or 90 day conversation-content settings.
  3. 03Delete with evidenceTracked propagation rather than a silent UI disappearance.
Open release gates

What we will not overclaim.

Required before GAIndependent penetration test

Scope, remediation evidence, and retest must be complete.

Required before GAExternal legal validation

GDPR and AI Act positioning, contracts, and notices require qualified counsel review.

Not claimedFormal certifications

Sourceform does not currently claim ISO 27001, SOC 2, or other third-party certification.

Need the detail?

Start with the architecture and the limits.

Read documentation Contact security