Trust & data protection

Your data works here. It doesn't live here.

SourceGeek connects to your ATS and other tools to answer questions and take actions you approve — without copying your database, without AI providers keeping a single prompt, and without changing a record unless a person says yes.

Nothing is copied

We don't sync, mirror, or crawl your systems. When you ask a question, SourceGeek fetches exactly the records needed to answer it over an encrypted connection, then closes it. Disconnect a connector and access ends immediately — there is no copy left behind.

Nothing is kept by AI providers

All AI processing runs through a single gateway to model providers under zero-data-retention terms: prompts and outputs are processed to answer your request, never stored, and never used to train models. Your candidates' data doesn't become anyone's training set.

Nothing changes without a human

Reading is automatic; writing never is. Before SourceGeek creates, updates, or deletes anything in your systems — or sends any message — it stops and asks. By default every change requires approval, your admins control the policy, and every action is logged.

What happens when you ask a question

Every request follows the same four steps — with no background jobs touching your data in between.

  1. 1

    You ask

    A recruiter asks a question or requests an action in plain language — for example, "Which candidates in our ATS match this vacancy?"

  2. 2

    We fetch on demand

    SourceGeek retrieves only the records needed for that request, over an encrypted connection. There is no import, no nightly sync, no crawler.

  3. 3

    AI processes, retains nothing

    The data passes through our AI gateway to produce the answer. Under our providers' zero-data-retention terms, prompts are not stored and are never used for training.

  4. 4

    You stay in control

    If the answer leads to a change in your ATS, SourceGeek asks for approval first and records the action — including who approved it — in an audit log.

Built-in safeguards

Data protection at SourceGeek isn't a policy document — it's how the product is built.

Approval before every change.
Create, update, delete, and send actions pause for human confirmation by default. Workspace admins decide how strict the policy is.
A full audit trail.
Every action on a connected system is logged with its outcome, the person who approved it, and a link to the record — visible to your admins at any time.
Encrypted credentials.
Connector credentials and OAuth tokens are stored AES-256 encrypted and are never written in plaintext.
Strict workspace isolation.
Every request is scoped to your workspace. Members of one workspace can never see another workspace's data.
Deletion that means it.
Delete your workspace and its chats, documents, memories, and audit logs are permanently erased. We keep only a content-free deletion receipt for 90 days.

Frequently Asked Questions

Can't find what you're looking for? Contact customer support team or check our support center.

Questions from your DPO or works council?

We're happy to go through everything in detail — how data flows, what is stored, and which sub-processors we use.

Ready to add a 24/7 AI Colleague?

Easy plug & play, no technical knowledge needed. Have your assistant ready in a matter of minutes.

Start Free trialNo credit card required
Book a demoPersonalized 30 min demo