Skip to content

What are sources?

A source is a document you import into ResponseHub so it can be used to answer questions. Sources are the raw material behind every answer: when ResponseHub drafts a response, it cites the source text it drew from, so a reviewer can check the answer against the original document.

Most sources are policy documents, but anything that helps answer a security questionnaire or an RFP is worth importing.

Your policies. These do most of the work. Typical examples:

  • Access control
  • Information security
  • Responsible AI
  • Disaster recovery

Supporting material about your product and organisation. Questionnaires and RFPs ask about more than policy, so include the documents that describe what you sell and how you operate — product data sheets, product overviews, and general information about your organisation.

Current penetration test reports. Import a pen test report if it is still up to date. An out-of-date report describes a system you no longer run, and answers drawn from it will be wrong.

Don’t import previous questionnaires as sources. They are far more useful imported into your knowledge base, where each question and answer becomes a reusable knowledge base item rather than a block of text to be searched.

ResponseHub accepts PDF, DOCX, DOC, ODT, RTF, PPTX, and PPT files. PDF and Word documents are preferred — they are the formats most policies already exist in, and they process most reliably.

Sources and the knowledge base are two different things, and answers can come from either. A source is a document you imported; a knowledge base item is an approved answer you have curated. For how ResponseHub chooses between them, see knowledge base vs sources.