Your rules apply before the AI sees anything.
Whichever AI your people use, SourceLace sits between it and your systems. Every question and every change, from your own AI app, the SourceLace app or an AI agent, passes through the same layers, in the same order, every time.
Every request passes through seven layers before it reaches your systems.
- 1Each person's own sign-inPeople connect each system with their own account wherever the system offers it, so its own permissions and sharing rules decide what they see. Connectors that use one shared account are labelled so, and an admin adds them knowingly.
- 2Access by groupAdmins choose which groups may use each system and object, and which may change them. Groups can come from your identity provider through single sign-on or SCIM provisioning (Preview).
- 3Data protectionHide sensitive fields so the AI never gets them, or mask them. Email addresses, phone numbers, US Social Security numbers, payment card numbers, IBANs and your own patterns are found automatically, in any text. The AI sees only placeholders such as [EMAIL_K3F9QX]; the real values are put back only for the people you allow, in the SourceLace app and in the changes they confirm.
- 4Changes only with a person's yesRead-only by default. Where an admin allows changes, each one is previewed field by field and sent only after a person confirms it.
- 5Nothing copiedQuery results are held for at most 30 minutes, encrypted with your organization's own key when stored, then deleted. Your admin can make that shorter.
- 6Tamper-evident audit trailEvery call, by every person, app and agent, recorded with who, what and when, never the data itself, and chained so a changed or deleted entry shows.
- 7Works with the AI you chooseBring any AI app and SourceLace sends nothing to an AI model itself. In the SourceLace app, use the AI included in your plan or your organization's own AI key. The same layers apply either way.
Your records aren't copied. Here is everything that is kept.
Query results are held for at most 30 minutes and never written to a database or a log. Files are read on demand and never copied or indexed. A few things last longer, all encrypted with a key unique to your organization.
- Saved chats and the files made in them. Chats in the SourceLace app are saved with the rows they show, and deleted after your retention period (30 days after last use by default).
- AI agents' run summaries and pending changes. Changes waiting for approval include the before and after values. Deleted with the agent and after your retention period.
- Sign-ins and secrets. Each person's sign-ins to your systems and your admins' secrets, including your own AI key. Never logged or shown again.
- Your setup. Skills, agent settings, groups and rules stay until you delete them. The audit trail holds who did what, never the rows returned or the values written.
People who leave lose access at once.
Sign in with Google, Microsoft or your own single sign-on, and require it for your domains. With SCIM provisioning (Preview), your identity provider adds people, keeps their groups up to date and deactivates them when they leave.
- Everything ends together. Removing someone ends their sessions and AI app connections, and removes their sign-ins to your systems. Their AI agents pause for an admin to decide on.
- No passwords of our own. For most systems people sign in on the system's own page, so SourceLace never sees their passwords. Multi-factor authentication is whatever your identity provider requires.
Answers for your security team.
Does SourceLace copy our data into its own store?
No. SourceLace reads your systems live. Query results are held for at most 30 minutes, then deleted, and files are read on demand and never indexed. The longer-lived exceptions are saved chats and the files made in them, and AI agents' run summaries and pending changes, all encrypted with your organization's own key and deleted after your retention period.
Will people see more than they can see today?
No. With personal sign-in, every call runs as the person, so the system's own permissions apply. Your admins can narrow that further with access by group and data protection rules. A few connectors can only use one shared account; they are labelled so, and an admin decides whether to add them and who may use them.
Can the AI change records in our systems?
Only where an admin has turned changes on for named objects of a system. Every change is previewed and sent only after a person confirms it, and previews expire within 10 minutes. SourceLace never sends email: mail connectors only make drafts.
Which AI model sees our data? Is it used for training?
With your own AI app, the model you chose there. In the SourceLace app, the AI included in your plan or your organization's own AI key. SourceLace does not train AI models on your data and does not send it to any AI provider other than the one your admin chose. Hidden fields never reach the AI, and masked values reach it only as placeholders.
Is our data separated from other customers' data?
Yes. Everything SourceLace keeps for your organization is tied to it, every request is checked against the signed-in person's organization, and your organization's secrets, chats and agent data are encrypted with your organization's own key.
Can SourceLace staff see our data?
SourceLace's operators manage your account, such as your plan and admins, on a page that never shows data from your systems, sign-ins, secrets or AI keys. Every change they make is recorded in your own audit trail under their name.
Where does SourceLace run? Can we keep everything in our own network?
SourceLace's cloud is hosted in the United States today. To keep agent runs inside your network, use a SourceLace Runner. To run all of SourceLace yourself, self-host it with Docker or Kubernetes (Preview).
Does SourceLace hold a security certification?
Not yet. SourceLace does not hold a certification or attestation today. The security questions page in the docs answers questionnaire items directly, including what is not in place yet.
More for your security team: Security and privacy · Security questions · Data protection · security@sourcelace.com