Add trusted knowledge
Import a public GitHub repository, upload PDF or DOCX files, connect a private Google Drive file, or paste text.
- Private GCS originals
- Asynchronous processing
- Visible processing status
Multi-tenant AI knowledge platform
SourceLoom indexes GitHub repositories and private documents, enforces workspace and document permissions before retrieval, and returns answers grounded in visible evidence.
Complete the personal details and authorization sections before submission.
[1] PERSONAL DETAILS [2] AUTHORIZATIONProduct
SourceLoom keeps original files, searchable evidence, identity, and authorization separate enough to operate safely, while presenting one clear workflow to the user.
Import a public GitHub repository, upload PDF or DOCX files, connect a private Google Drive file, or paste text.
PostgreSQL RLS isolates workspaces. Document ACLs restrict resources inside each workspace before any text reaches the model.
Inspect original passages, generate one cited answer, or use a bounded research agent when intermediate evidence changes the next search.
Interactive product tour
This tour uses prepared sample data. It demonstrates the product workflow without uploading a file or contacting the live application.
The user grants read-only Drive access and submits a file link. The file does not need to be public, and SourceLoom never edits it.
Architecture
The write path turns external content into a recoverable index. The read path turns a verified identity and question into authorized evidence.
Security model
Identity comes from a verified session. Authorization is enforced before retrieval. Tool calls receive server-derived tenant and principal context.
State, nonce, PKCE, opaque sessions, CSRF protection, and verified membership checks.
A restricted database role reads transaction-local tenant context on every protected query.
Search, direct reads, citations, conversations, and resource listings use the same principal rules.
Strict schemas, no model-controlled identity, and explicit step, tool, time, and context budgets.
Engineering decisions
Keeps tenant metadata, document status, ACLs, text, and vectors in one controlled query path. A separate service becomes justified only after measured scale or filtered-ANN limits.
GCS stores immutable originals and handles resumable upload. PostgreSQL stores transactional metadata, status, chunks, embeddings, and authorization.
The source record and publish intent commit together. Redelivery is expected, so consumers make the final database effect idempotent.
A single VM does not need cluster scheduling. Kubernetes becomes useful when multi-node availability, independent scaling, and operational ownership are real requirements.
Recorded demonstration
The final video will show an Auth0 login, a private Google Drive import, asynchronous indexing, permission-aware search, a cited answer, the research agent, and access control.
Current scope
Public HTTPS, invitation login, team access, GitHub and private document ingestion, hybrid retrieval, cited answers, bounded agent runs, and operational status.
Tenant isolation, fresh database migrations, a real private Google Drive PDF, GCS retention, two indexed chunks, and permission-aware retrieval.
Multi-node availability, durable broker storage, OAuth publication, restore drills, managed secrets, file scanning, load testing, and SLOs.
SourceLoom AI
The portfolio stays online. The full application can be started for a live walkthrough.