# What are sources?

A source is a document you import into ResponseHub so it can be used to answer
questions. Sources are the raw material behind every answer: when ResponseHub
drafts a response, it cites the source text it drew from, so a reviewer can check
the answer against the original document.

Most sources are policy documents, but anything that helps answer a security
questionnaire or an RFP is worth importing.

## What to import

**Your policies.** These do most of the work. Typical examples:

- Access control
- Information security
- Responsible AI
- Disaster recovery

**Supporting material about your product and organisation.** Questionnaires and
RFPs ask about more than policy, so include the documents that describe what you
sell and how you operate — product data sheets, product overviews, and general
information about your organisation.

**Current penetration test reports.** Import a pen test report if it is still up
to date. An out-of-date report describes a system you no longer run, and answers
drawn from it will be wrong.

## What not to import

Don't import previous questionnaires as sources. They are far more useful
imported into your knowledge base, where each question and answer becomes a
reusable [knowledge base item](/knowledge-base/knowledge-base-items/) rather than
a block of text to be searched.

**Answered questionnaires belong in the knowledge base:** See [importing from completed questionnaires](/knowledge-base/importing-from-completed-questionnaires/)
for how to bring previous answers in.

## Supported formats

ResponseHub accepts PDF, DOCX, DOC, ODT, RTF, PPTX, and PPT files. **PDF and Word
documents are preferred** — they are the formats most policies already exist in,
and they process most reliably.

## Sources and the knowledge base

Sources and the knowledge base are two different things, and answers can come
from either. A source is a document you imported; a knowledge base item is an
approved answer you have curated. For how ResponseHub chooses between them, see
[knowledge base vs sources](/how-questions-are-answered/kb-vs-sources/).

## Next steps

- [Import your sources](/sources/importing-sources/)
- [View a source](/sources/viewing-sources/)
- [Update a source when a policy changes](/sources/updating-sources/)