
Sourcery typical implementation process:
Choose Your Integration: Decide whether to add Sourcery to your GitHub/GitLab project or install the IDE plugin (e.g., for VS Code).
Sign Up and Authenticate: Register for a Sourcery account and link your tool (via OAuth or API key).
Add to Repo/Project: For repository integration, install the Sourcery GitHub/GitLab app or add the relevant extension for your IDE or CI system.
Configure Access: Set permissions—choose which repos or projects Sourcery can access and review.
Set Up Team Rules (Optional): Define team standards, coding guides, and any custom review instructions as desired.
Start Reviewing: Open a pull request or commit code—Sourcery will analyze and provide instant feedback, suggestions, summaries, and comments automatically.
Sourcery can be customized to fit specific business needs, with several robust customization and configuration options available:
Custom Code Quality Rules: You can create your own project-specific rules using YAML configuration files or directly generate rules within your IDE. This allows you to enforce organization-specific coding standards, styles, and policies.
Rule Generator: Sourcery provides tools such as the Rules Generator, which enables you to automatically create project architecture rules (e.g., package import dependencies, naming conventions) to govern your codebase’s structure and design.
Optional Rule Bundling: You can enable or disable specific rule sets, including optional or organization-specific rules, through configuration files (e.g., .sourcery.yaml), which allows granular control over code review enforcement across different teams and projects.
IDE and CI Integration: Customization extends to choosing integration types that best fit your workflow. Teams can deploy Sourcery within IDEs, in CI/CD pipelines, or as part of GitHub/GitLab code reviews, adapting to their existing developer environment.
Privacy & Deployment Options: For organizations needing compliance or enhanced data privacy, Sourcery offers self-hosted/on-premise deployment, ensuring that code never leaves your controlled infrastructure. You can also define the LLM endpoints used, maximizing security.
Team-Specific Settings: Teams can fine-tune review criteria, enforce team-wide refactoring policies, and tailor recommendations based on collective feedback and historical review practices, making the tool responsive to evolving standards and preferences.
Best Practice Enforcement: Sourcery can be configured to prioritize or require adherence to industry and organizational best practices, actively guiding developers through in-line suggestions, automated refactoring, and style guide checks.
Custom Path and Scope: You can specify which paths or file types within your repository Sourcery analyzes, allowing targeted review of mission-critical code or exclusions of experimental/legacy modules.
Sourcery does not generally require separate setup, maintenance, or support fees for standard users—costs are predominantly subscription-based and plan-dependent:
Open Source Repos: Free to use for public/open source projects. No setup or ongoing fees.
Pro Plan: $10–15 per seat/month, or $120/year per seat for private repos. This covers code review features, pull request summaries, and basic support.
Team Plan: $24–30 per seat/month, includes everything in Pro plus repo analytics, secrets scanning, SAST, advanced integrations, and custom rules—suitable for teams needing higher-level features.
Enterprise Plan: Custom pricing (contact sales); includes everything in Team plus options for self-hosting, priority support, a customer success manager, invoice billing, and advanced enterprise controls.
Support & Success: Pro and Team plans cover standard support. Enterprise plans offer priority support and a dedicated customer success manager, possibly incurring higher costs.
Self-Hosting & Custom Deployment: Available only via Enterprise plans; this may entail additional costs—details are not public but are quote-based.
No Setup or Onboarding Fees for Standard Cloud: All plans provide self-serve setup; there is no standard setup fee listed for cloud-hosted versions.
Maintenance: Covered by the subscription fee for cloud offerings. Maintenance for self-hosted deployments (available in Enterprise) may incur separate costs, but specifics require direct inquiry.
Discounts: Annual billing is discounted by 20% over monthly billing. You only pay for assigned seats, not the entire organization.
Sourcery offers several forms of training and support for new users:
Comprehensive Documentation & Tutorials: Sourcery provides detailed "Getting Started" guides, step-by-step tutorials, and FAQ resources to help users onboard quickly and independently.
In-Product Guidance: Sourcery includes in-app onboarding tips, code examples, and inline suggestions so users can learn features contextually as they work (e.g., in VS Code, GitHub, or GitLab).
Customer Support via Multiple Channels: Users can reach Sourcery support by email ([email protected]), via an in-app help icon or dashboard, or by submitting tickets through the chat window in the app. The support team aims to respond promptly.
Video Guides and Community Tutorials: There are YouTube walkthroughs and community-driven content showing how to leverage Sourcery features for various languages and workflows.
Free Trial and Self-Service Onboarding: All new users can try the Pro version free for 14days, allowing them to explore all features with self-guided resources during the onboarding phase.
Priority Support and Dedicated Success for Enterprise: Business and enterprise plans include priority support, with higher tiers offering a dedicated customer success manager to assist with onboarding, training, and ongoing best practices.
Sourcery implements a set of security measures to protect user data and code:
No Code Stored by Default: Sourcery’s core analysis operates locally within your IDE or CI pipeline; no code is stored on their servers for its main review and refactoring functions. For cloud-based AI assistant features, code snippets sent to LLM providers are never stored by Sourcery.
Zero Retention Option: For their AI-powered coding assistant, Sourcery offers a "zero retention" mode (e.g., via Anthropic), ensuring that code and data are never retained by third-party LLM providers. Standard retention for OpenAI and Google is capped at 30days, but can be set to zero with an appropriate license.
No Data Used for Training: Neither Sourcery nor its LLM partners (OpenAI, Anthropic, Google) use your code for training language models.
End-to-End Encryption: All data transmitted between a user’s environment and Sourcery/third-party services uses secure, encrypted channels.
Strict Data Minimization: The only data collected are anonymized usage analytics and telemetry (which you can opt out of) or information needed for account management (name, email). No raw code is collected for analytics or sales.
User-Controlled Data: Users have full rights to access, correct, withdraw, or erase their personal data at any time. You can request deletion of all personal information under GDPR principles.
Immediate Source Code Deletion: Code that is processed as part of code review services (e.g., via pull requests) is deleted immediately after processing—never stored past the processing session.
Self-Hosted/On-Premise Deployments: Enterprise customers can deploy self-hosted versions or use their own model endpoints, ensuring that code never leaves their own infrastructure for maximum security and compliance.
Access Control: All integrations (GitHub, GitLab, IDEs) use secure tokens and permissions to grant or revoke Sourcery’s access as needed. You can control which repos Sourcery can access at all times.
Regulatory Compliance: Compliance with GDPR and other regulations is maintained through detailed data retention and privacy policies, as well as integration with third-party error monitoring (e.g., Sentry.io) that is itself GDPR and EU–US Privacy Shield compliant.
Sourcery releases updates frequently, often several times per month, addressing new features, bug fixes, and improvements across its core code review engine, IDE plugins, and integrations. These updates are managed transparently and efficiently:
Changelog and Release Notes: Updates are thoroughly documented in the [official changelog], showing recent and historical changes, feature rollouts, bug fixes, and improvements. This provides users with clear visibility into enhancements and release cadence.
Automatic Updates: For cloud-based and SaaS users, updates and new features are deployed server-side and become available without user intervention.
IDE & Plugin Updates: Sourcery extensions for IDEs (like VS Code or JetBrains) are updated through their respective marketplaces. Users are typically notified of new releases and can update their plugins directly from the IDE.
GitHub/GitLab Bot Improvements: The Sourcery bot that reviews pull requests is updated continuously; new bot features or review behaviors are rolled out to all users automatically.
Release Frequency: GitHub release logs show new pre-releases and full releases multiple times each month, reflecting the platform’s ongoing commitment to stability and feature growth.
Sourcery’s policy on data ownership and portability is structured to respect user rights and promote transparency:
Code and Data Ownership: You retain full intellectual property rights over both the code you input and the output generated by Sourcery. Sourcery explicitly states it does not claim ownership over any code you process or produce with their services—whether using free, Pro, or Team tiers.
No Code Storage: Your source code is never stored after review or processing. Code is only used for analysis during the session and deleted immediately after; this reduces risks related to ownership disputes or unauthorized access.
Personal Data and Portability Rights: Sourcery enables you to:
Request a copy of your personal data in a machine-readable format (data portability).
Request deletion (right to erasure) or correction of your personal data.
Withdraw consent for further data processing at any time.
GDPR and Regulatory Compliance: Sourcery follows GDPR and other data protection regulations, which strengthen users’ rights around accessing, exporting, and managing their personal and code data. Erasure or export requests are processed within 30days upon verification.
Portability Procedure: Users can initiate data portability or deletion requests by contacting Sourcery ([email protected]). Data such as account details and analytics can be exported or erased upon request, subject to identity verification and applicable legal exceptions.
Sourcery’s terms and conditions for contract renewal and cancellation include the following core points:
User-Initiated Termination: You can terminate your access to Sourcery’s services at any time, for any reason, by ceasing use of the application or by requesting account deletion (email: [email protected]).
Company-Initiated Termination: Sourcery reserves the right to cancel or terminate your account if you violate their terms, use the service for illegal activities, or attempt to reverse engineer their products or services.
Intellectual Property: All your input code and output from Sourcery’s code review tools remain your intellectual property, even upon cancellation or termination.
Licenses End with Termination: All granted licenses (for Free, Pro, or Team usage) are revocable and terminate when your access to the services ends, whether you cancel or they terminate your account.
No Refunds and “As-Is” Service: The service is provided “as is” and “as available.” There are no special refund policies or guarantees unless otherwise specified at point of purchase or under special promotion.
Survival of Terms: Certain terms—such as indemnity, intellectual property, and disclaimers—remain in force even after your contract or access to services ends.
Sourcery meets several key compliance standards centered around data protection and responsible use of AI in software development:
GDPR Compliance: Sourcery is fully compliant with the European General Data Protection Regulation (GDPR) and designates itself as a data processor, processing client data according to strict privacy and security guidelines. Users have rights to access, portability, correction, and erasure of their personal data, and can request these at any time. Personal data is processed only as necessary for the provision of services and never for model training.
Data Retention and Sovereignty: Source code is never stored beyond the session, and all data retention is kept to a minimum in line with GDPR’s “privacy by design” principles. Users can configure global data processing (including zero retention for AI features).
Processor & Sub-Processor Controls: All subprocessors (e.g., payment, analytics, authentication) must adhere to Sourcery’s Data Processing Agreement and are vetted for strong data protection. Data is primarily stored within the EEA, and any transfer outside the EEA is subject to client control and EU model clauses.
Security and DevSecOps Integration: Sourcery proactively identifies and helps remediate security issues within code, supporting compliance with internal best practice standards as well as broader DevSecOps frameworks.
Sourcery Certified™ (Trade and Process): For advanced supply chain and commercial transparency, Sourcery uses third-party and automated verification (including zero-knowledge proofs for process validation), providing objective and auditable compliance support for larger organizations.
Notification of Data Breaches: The company is obligated to inform clients promptly in the event of a personal data breach, as outlined in its Data Processing Agreement (as per GDPR requirements).
Right to Audit and Documentation: Clients can request further documentation to support audit readiness or compliance assessment as part of the contractual agreement.