The front page makes the promise: search everything, copy nothing. This page is for the people who have to deploy it, secure it and sign off on it. It starts with what you get, then shows how each part works and what it never touches.
Copy-everything search ingests your documents and copies your access-control lists into a map that must be kept current. SWIRL does neither. Here is what that means for the person who has to sign the security review.
Each query goes to the source systems at request time and the results are re-ranked in memory. Full text fetched for an answer is held only for the duration of that request. SWIRL's own database stores metadata: users, groups, SearchProvider definitions and per-user result pointers.
SSO over OAuth2 and OpenID Connect signs the user in. Per-source OAuth2 passes that user's own token to Microsoft 365, Google Workspace, Box and the rest, so each system applies its own access control at the moment of the query. There is no ACL mirror, so nothing drifts.
On-prem, private VPC or your own cloud tenant, via Docker Compose, Kubernetes, a one-click Railway deployment or the Azure Marketplace. Any LLM, including a fully on-prem model served by Ollama, so inference stays inside your walls too.
SWIRL Corporation has no access to your data, your user identities or your query logs unless you choose to share them for support. Delete a document at the source and there is nothing to purge from us.
The controls SWIRL provides and the controls you own are documented in the Security Guide. Customers may pen-test their own deployment at any time.
SWIRL fans a single query out across all your connected systems in parallel - documents, email, chat, tickets, code, the web - then re-ranks and de-duplicates what comes back. No data moves, and each system's own permissions are honored on every call.



Not vector distance - judgment. SWIRL ranks in three passes, and both models run locally: nothing is sent over the wire, and ranking needs no index of your content to work against.
E5-Large-V2 embeddings with title-aware chunking, then hybrid keyword+vector fusion (RRF), computed in process as the results come back.MS-MARCO cross-encoder reads the query and document together - scoring real relevance, not similarity.
The real architecture, drawn from the code. Pick a scenario and watch a query fan out, get scored on one scale and come back cited.
Forty-two components, drawn from the code. The interactive map needs a wider screen.
Open the full-screen mapA 30-minute working session against a slice of your own systems: the results, the citations and the permission boundary, on your data. You'll be talking to the person who wrote it.
Building a product? SWIRL for Embedding →