Measured: 471 of 472 answers grounded in file-and-line citations across five public repositories, file-hit 0.71–0.88. See the numbers

The governed gateway between AI agents and private code

Say yes to AI agents on private code, with policy on what they read and proof of what they saw.

SourceVault runs on hardware you already own and sits between agents and your repositories, so every read is gated by policy and every access leaves evidence you can verify offline. Behind the gate, agents get what makes them effective — grounded, file-and-line-cited answers over your code and its entire git history. Nothing is sent to a third party.

What buyers get

  • SourceVault Gateway is the governing layer: an access policy over what AI can read, and secrets redacted from every answer. It comes with every license, and the free trial runs it on one repository.
  • Every access lands in a tamper-evident audit log; AI-authored changes carry signed provenance.
  • An operator console shows what agents accessed and what was stopped, and verifies the audit chain in one click.
  • A dashboard with cited answers, a full source viewer, watches, and runbook export.
  • Git-history answers and module overviews, with retrieval tuned for agents. A cloud indexer sees none of it.
  • SourceVault indexes GitHub, GitLab, and Bitbucket repositories, as well as any folder on disk.
  • An MCP server for any MCP client, plus the Hermes plugin — every surface behind the same gate.
  • One-command install on macOS, Linux, or Windows (WSL2). A 7-day free trial of the full product on one source, no account or card required.

The problem

Hosted AI tools break down when the code is private.

Most code assistants upload your repository and answer from a lossy slice held in a cloud context window. On a large or sensitive repo, that creates privacy and compliance risk, and the answers get weak.

And even when the tooling is private, a security owner still has to answer for it: which repos and files can agents touch, and what exactly did the AI read last quarter? SourceVault is built for teams that need to permit AI on private code. It answers both questions on infrastructure you own: policy decides every read, and the log shows what the AI actually saw.

The engine

Grounded answers from exact reads of a local index.

The engine implements textbook retrieval patterns, built directly on a local SQLite vector index and Ollama, with an optional Qdrant engine that SourceVault runs for you when full git history takes a repository to serious scale. The stack stays small enough to audit line by line.

01

Hybrid retrieval

Each query combines semantic search and exact keyword matching, then fuses the rankings so the strongest results rise to the top.

02

Code-aware chunking

Files are split along function and class boundaries, so every result maps to readable code with exact line ranges.

03

Context-aware embeddings

Each chunk is embedded with its path and symbol names, so the vector store knows where each piece of code lives in the repository as well as what it says.

04

Grounded answers

Ask mode checks whether it has enough context, retrieves again if needed, and answers only from source-backed snippets instead of guessing.

Watch the full walkthrough, video included

Cost model

Retrieval is cheaper than re-reading the repo.

An AI agent will re-read a whole file to find one function, then drag that stale context forward turn after turn. The waste compounds with every question a developer asks, and per-seat plans meter all of it. SourceVault answers from a bounded budget of cited file and line ranges instead. Repeated questions return from cache without a model call, and local models have no meter at all.

Per-seat feesNone. Runs for the whole team on one machine you control
Per-token billingNone for local answers; repeated questions return from cache with zero model calls
Context per answerA bounded budget (about 6k tokens by default) of cited file and line ranges
Source code egressNone. Nothing is uploaded, logged, or retained by a third party

Why SourceVault

What you get beyond code search.

The engine tracks how your code connects, re-checks its answers as the code changes, and controls what AI tools are allowed to read. All of it is driven from a browser dashboard the whole team can use. A few highlights:

100% local by design

Ollama generates the embeddings and a local SQLite file stores the vectors, both on your own machine — no vector database service to run. The model that writes the answer runs there too.

SourceVault GatewayEvery tier

Governed AI access to your code, in every license. The Sentinel policy gates which files can be read at all, a DLP pass redacts secrets from every answer before delivery, each decision lands in a tamper-evident hash-chained audit log, and AI-authored security-relevant commits get signed provenance attestations. Standard on every tier, and the free trial runs it on one repository.

Git history answers

Commit messages are indexed alongside code, so questions like "why was this changed?" and "when did this break?" are answered from the actual commits. Cloud indexers can't do this, since they only ever see a snapshot of the tree.

Multi-repo AskPro

Ask one question across every indexed repository at once, with each citation tagged by repo. "How do the frontend and backend handle this?" comes back as a single answer. Standard from Pro up.

Watches

Pin a question as a standing check. After every reindex it runs again and flags you if the cited answer has drifted. Useful for questions like "did the auth flow change this sprint?"

Works with your AI tools

An MCP server exposes the same engine to OpenClaw and any other MCP client, which get bounded, cited context instead of re-reading files. The server itself is local-only. Pair it with a local-model client and the whole loop runs offline; a cloud-backed client sends what it retrieves to its own vendor, by your choice.

See all 30+ capabilities on the features page

Pricing

Free for 7 days, then a one-time payment.

Every license carries the SourceVault Gateway, the same governed path the free trial runs. What changes between tiers is the number of sources you index, where a source is a repository or a local folder, and how many machines run it. There are no per-seat or per-token fees, and loose files you add individually share a single source slot.

Start with the free trial

One command installs the full product with one source for 7 days, with the SourceVault Gateway running on that repository. No account, no card. If it can't answer questions about your code with file-and-line citations, don't buy it.

Install free

Starter

$1,350 one-time

For one engineer running coding agents on their own private repos.

  • Up to 3 indexed sources (repos or local folders)
  • One machine
  • Dashboard, Hermes plugin, MCP server
  • Git-history answers and module overviews
  • Webhook-driven reindex on every push; watches that re-check themselves

Team

From $8,200 one-time

The same product rolled out to a team: several machines, a large monorepo, a guided setup.

  • Up to 4 machines, shared team setup
  • No source cap: 15+ sources or a large monorepo
  • Security-focused file exclusions
  • Team onboarding and maintenance runbook
  • Everything in Pro
Start with Team

In every tier

SourceVault Gateway

An access policy over what AI can read, secrets redacted from every answer, a tamper-evident audit chain, signed AI-change provenance, and named agent identities. The same governed path the free trial runs.

Operator console

What agents accessed, what was stopped, and chain verification in one click.

12 months of updates

The version you install is yours forever; renewing updates later costs a fraction of list price.

A key, not an account

The license key arrives by email, activates instantly, and verifies offline. No login, no phone-home.

Add-ons

Priority Support Subscription

The one optional subscription: a support SLA plus hands-on help, model and resource tuning for your hardware, and reindex strategy when embedding models change. Flat $195/mo for any plan. Requires an active SourceVault license (buy with the same email). Cancel anytime.

Updates renewal Existing customers

Your license and installed version work forever. When your 12-month updates window ends, renew to keep receiving new releases: Starter $550, Pro $1,850, one-time. The fresh key arrives by email and replaces the old one in the dashboard's License settings.

A "From" price is a floor; your quote is fixed before work starts, and you get a straight recommendation even if the right answer is the smaller package. Every license carries a 14-day money-back guarantee, and nothing ever auto-renews; the details are in the billing & refund policy. Starter customers can upgrade to Pro any time for the difference in list prices ($3,150 today), from the dashboard's Settings once you're licensed, or email support.

Deployment

One command on every platform.

The models, the index, and the dashboard all run on machines you control. One command installs everything on macOS, Linux, or Windows (WSL2), or use the shared Docker Compose deploy where teammates on any OS connect through the browser. Every install includes the 7-day free trial.

Read the full install guide

Questions?

Talk to a human before you buy.

Team and Enterprise rollouts, air-gapped installs, checkout trouble, or anything the trial can't settle: email us and you'll get a straight recommendation, usually the same day. For install help, Discord is fastest.