For CIOs, architects & technical evaluators

What SWIRL never does to your data.

The front page makes the promise: search everything, copy nothing. This page is for the people who have to deploy it, secure it and sign off on it. It starts with what you get, then shows how each part works and what it never touches.

What you get

One search. The version that governs.
A cited answer.

Everything, at once
Every system, one query.
Microsoft 365, databases, existing search indexes and internal APIs, queried in parallel and back in seconds. Nothing is moved to make it findable.
The version that governs
The one your organization approved, on top.
Results from incompatible systems are re-scored on one scale, de-duplicated and grouped, so the approved version leads. The answer is written from that document and cites it.
Your agents, same rules
Claude, Copilot and your own agents, over MCP.
The identical search, under the same permissions, with the same citations. An agent sees only what its user can see.
The zero-copy guarantee, in your terms

No index to secure.
No permission map to keep in sync.

Copy-everything search ingests your documents and copies your access-control lists into a map that must be kept current. SWIRL does neither. Here is what that means for the person who has to sign the security review.

Your content

Dispatched, not ingested.

Each query goes to the source systems at request time and the results are re-ranked in memory. Full text fetched for an answer is held only for the duration of that request. SWIRL's own database stores metadata: users, groups, SearchProvider definitions and per-user result pointers.

Your permissions

Decided by the source, per user, per query.

SSO over OAuth2 and OpenID Connect signs the user in. Per-source OAuth2 passes that user's own token to Microsoft 365, Google Workspace, Box and the rest, so each system applies its own access control at the moment of the query. There is no ACL mirror, so nothing drifts.

Your boundary

Runs where you already run.

On-prem, private VPC or your own cloud tenant, via Docker Compose, Kubernetes, a one-click Railway deployment or the Azure Marketplace. Any LLM, including a fully on-prem model served by Ollama, so inference stays inside your walls too.

Your vendor

Sees nothing.

SWIRL Corporation has no access to your data, your user identities or your query logs unless you choose to share them for support. Delete a document at the source and there is nothing to purge from us.

The controls SWIRL provides and the controls you own are documented in the Security Guide. Customers may pen-test their own deployment at any time.

Federated retrieval

One query. Every system.
At once.

SWIRL fans a single query out across all your connected systems in parallel - documents, email, chat, tickets, code, the web - then re-ranks and de-duplicates what comes back. No data moves, and each system's own permissions are honored on every call.

150+ sources in parallelZero ETLPermissions enforced at source
A single query entered on the SWIRL dashboard
1. One query in.
SWIRL searching across every connected source in parallel
2. Every source, in parallel.
SWIRL ranked results federated from hundreds of millions of documents in seconds
3. Ranked results, in seconds.
View all 150+ connectors →
Relevance · runs locally, in your tenant

Three passes to the right answer.

Not vector distance - judgment. SWIRL ranks in three passes, and both models run locally: nothing is sent over the wire, and ranking needs no index of your content to work against.

1
Federate & match
Keyword + BM25 across every source. Quoted phrases and exact terms are honored first - a quote must match.
2
Embedding re-rank
E5-Large-V2 embeddings with title-aware chunking, then hybrid keyword+vector fusion (RRF), computed in process as the results come back.
3
Cross-encoder re-rank
MS-MARCO cross-encoder reads the query and document together - scoring real relevance, not similarity.
E5-Large-V2MS-MARCO cross-encoderBM25 + RRFAny LLM, incl. on-prem
Recall-rate chart: SWIRL hybrid re-rank beats vector-only and keyword-only
Independent corroboration
Meta's XetHub benchmarked all three. Keyword-only came last, vector-only did better, hybrid re-rank won - the approach SWIRL ships by default.
"No vector database necessary." - XetHub, 2024 (archived)
The architecture

Follow a search
through the system.

The real architecture, drawn from the code. Pick a scenario and watch a query fan out, get scored on one scale and come back cited.

SWIRL 5 - Architecture
The SWIRL architecture map

Forty-two components, drawn from the code. The interactive map needs a wider screen.

Open the full-screen map

See it run on your systems.
Bring the auditor's questions.

A 30-minute working session against a slice of your own systems: the results, the citations and the permission boundary, on your data. You'll be talking to the person who wrote it.

Building a product? SWIRL for Embedding →