Security

The strongest thing about how SourceSecure is built is that the sensitive work happens on your computer, so most of what a breach of ours could expose does not exist on our side.

Last updated 26 September 2026

The design, which is the main thing

The strongest security property of SourceSecure is not a control we operate. It is that the sensitive work happens on the user's own computer, so most of what a breach of ours could expose does not exist on our side.

Messages and attached documents are read, recognised and redacted inside the browser. The model that recognises names and places is a file inside the extension, not a service we run. Nothing about the content reaches us.

What reaches us is the firm's account details, and counts. There is no field in the daily report through which a sentence could travel, and a test walks every field and fails if one could.

What the extension can reach

The extension asks Chrome for permission to run on these addresses and no others: chatgpt.com, chat.openai.com, claude.ai, copilot.com, www.copilot.com, copilot.microsoft.com, copilot.cloud.microsoft, m365.cloud.microsoft, gemini.google.com, perplexity.ai, www.perplexity.ai, grok.com, chat.deepseek.com, meta.ai, www.meta.ai, chat.mistral.ai, notebook.google.com and notebooklm.google.com, plus sourcesecure.ca so it can be connected to your account, and coach-lasowp7xjq-nn.a.run.app, the coaching service's own address, for coaching answers that are written onto the screen as they arrive.

It has no permission to read any other site, no permission to read your browsing history, your bookmarks or your downloads, and no ability to reach a site you have not opened yourself.

Its other permissions are storage, so your settings survive a restart; alarms, for the once a day licence check and for noticing when a pause has run out; offscreen, so the model can run in one place rather than in every tab; and scripting, so a tab still works after the extension updates underneath it.

Signing in

There are no passwords, so there are no passwords to steal, reuse or leak. Signing in is either Google, or a single use link emailed to an address you own.

Sign-in is handled by Firebase Authentication. Every call to our API carries the token Firebase issued and the server checks it; a page hiding a button is a convenience, the server refusing the request is the protection.

Being an admin is checked on the server for every action that manages a team, not just when the page is drawn.

The browser's licence

When a browser is connected to an account it is given a secret. We store only a one way hash of that secret, never the secret itself, so our database cannot be used to impersonate a browser.

The daily check confirms the firm is still paying and carries the firm's word lists back to the browser, and, to a Guard 360 seat, the firm's profile. For everybody, it is the only scheduled call the extension makes.

For somebody with prompt coaching on, two more things run on a timer. Once an hour the extension looks at whether last week's note is due, which asks the coaching service for one note a week at most. And while an AI chat site is open and in view, it sends a wake-up call every few minutes that carries nothing at all, so a tip does not wait for the service to start. Switching coaching off stops both.

Where the data sits

Google Cloud Firestore in northamerica-northeast1, which is Montreal, Canada. The functions serving this site and the API run in the same region.

Google encrypts data at rest and in transit as standard. Every connection to this site and the API is over HTTPS. The database refuses browsers entirely: nothing reads it directly, only our server does, after checking who is asking.

Every page, including those the API and the coaching service send directly, carries a Content-Security-Policy that lets it run scripts only from this site and connect only to this site and Google's sign in, so a script slipped into a page would be refused by the browser. Pages also refuse to be framed by other sites, tell browsers to use the secure address for a year, and send X-Content-Type-Options and Referrer-Policy headers. The site sets no cookies of its own, and loads its fonts from its own servers rather than from Google.

What does leave

Prompt coaching, on Guard Pro and Guard 360 seats, and reply marks, on Guard 360 seats, send redacted conversation text to OpenAI. Before it goes, our server checks every piece of it again for anything that looks like an email address, a phone number or a long number, and refuses to send rather than cleaning it quietly, because a leak getting that far means the extension has a fault worth fixing.

Coaching requests go to sourcesecure.ca, except those whose answer is written onto the screen as it arrives, which go straight to the coaching service's own address on Google Cloud Run, coach-lasowp7xjq-nn.a.run.app. It is the same service, in the same Montreal region; the website's front door holds a streamed answer back until it is complete, which defeats the point. It answers only SourceSecure's own extension, and refuses any request that is not from a connected browser on a paying firm.

Nothing from a coaching request or a reply check is stored. The facts read for a person's vault come back to their browser and are kept there only.

A fact somebody chooses to suggest for their firm's profile is sent to sourcesecure.ca and held for the admin, after the same check for anything that looks like an email address, a phone number or a long number.

Any person can switch coaching off for their own browser, and reply marks with it, and with it off nothing they type leaves their computer for any reason.

What we do not have yet

SourceSecure is a young product and this section is here because the alternative is implying otherwise.

There is no SOC 2 report, no ISO 27001 certification, no independent penetration test and no bug bounty. We have not had a third party audit the code.

There is no single sign on for enterprises, no audit log of admin actions, and no self serve account deletion.

If any of these matters to your firm, tell us. Knowing which one blocks a purchase is how it gets prioritised, and we would rather hear it than guess.

Telling us about a problem

If you find a security problem, email support@sourcesecure.ca with enough detail to reproduce it. We will confirm we have it within two working days and tell you what we are doing about it.

We will not take legal action against anybody who reports a problem in good faith and does not access other firms' data while finding it.

Getting in touch

Email support@sourcesecure.ca. SourceSecure is operated by JOLIVE Labs Inc.