Compliance

The compliance program

What the platform's attestations mean, which artifacts exist for a review, how to get them, and how you hear about changes that affect you.

Attestations

Context holds a SOC 2 Type 2 attestation. A Type 2 report is an independent auditor's examination of the controls behind a service — how access is granted, how changes ship, how incidents are handled — tested for operating effectiveness over a period of time rather than described at a point in time. The current report is available through the document library below.

Context's information security management system is certified to ISO 27001, the international standard for how an organization establishes, operates, and continually improves its security management. Context also holds AIUC-1, a certification of compliance for AI agent systems. Both certificates are in the same library.

When a new audit completes, it is added to this page and announced in the updates log; for the current status of anything in between, ask security@context.ai.

  • SOC 2 Type 2

    Independent audit of the security controls behind the platform, tested over a period rather than at a point in time. Report available on request.

  • AIUC-1

    Certification of compliance for AI agent systems. Certificate available on request.

  • ISO 27001

    Certification of the information security management system. Certificate available on request.

Requesting audit artifacts

These are the audit artifacts available for a security review. Requests go to the security team with your name, company, and the documents you need; documents that need an NDA go out after it is signed.

The DPA formalizes this: Context makes available the information reasonably necessary to demonstrate compliance, including summaries of third-party audit reports and certifications. Customers also hold a contractual audit right, exercisable once per twelve-month period on thirty days' notice; where adequate, the audit is satisfied by Context's then-current audit reports.

  • SOC 2 Type 2 attestation report

    The current independent audit report for the Context platform.

  • SOC 2 bridge letter

    Covers the gap between the report's audit period and today.

  • Penetration-testing report (latest)

    The most recent third-party penetration test of the platform.

  • AIUC-1 certificate

    Certification of compliance for AI agent systems.

  • ISO 27001 certificate

    Certification of the information security management system.

  • CAIQ security questionnaire

    Pre-completed Consensus Assessments Initiative Questionnaire for self-serve review.

  • Security policies (combined)

    The policies of the written information security program, combined in one document.

  • Security & compliance program update

    Point-in-time summary of the compliance program and what changed.

Procurement paperwork — the W-9 and evidence of insurance — lives in the document library alongside the public policies.

Change notifications

Subprocessor changes carry advance notice: the DPA commits to notifying customers at least ten days before a new subprocessor processes customer personal data, with a written objection right. If an objection cannot be reasonably accommodated, the affected services can be terminated with a pro-rata refund.

Security incidents follow the DPA's breach clause: notification without undue delay after Context becomes aware of a personal data breach affecting customer personal data, with the information you need to meet your own notification obligations.

Routine program changes — new attestations, refreshed reports, subprocessor-list updates — land in the trust center's updates log. To get them by email, subscribe via security@context.ai.

Request documentation

The document library covers audit reports, assessments, and procurement paperwork. Request what your review needs; anything that requires an NDA is shared once it is in place.

security@context.ai

Also documented: Deployment models · Identity & authorization · Data handling

Request access

Tell us who you are and what your review needs.

Resources