Compliance

The compliance program

Which security artifacts exist for a review, how to request them, and how you hear about changes that affect you.

Attestations

Independent audit reports and attestations are provided on request and as audits complete. For the current status of the compliance program — which reports are available and under what terms — ask security@context.ai.

When a new audit completes, it is added to this page and announced in the updates log.

Requesting audit artifacts

These are the audit artifacts available for a security review. Requests go to the security team with your name, company, and the documents you need; documents that need an NDA go out after it is signed.

The DPA formalizes this: Context makes available the information reasonably necessary to demonstrate compliance, including summaries of third-party audit reports and certifications. Customers also hold a contractual audit right, exercisable once per twelve-month period on thirty days' notice; where adequate, the audit is satisfied by Context's then-current audit reports.

  • Penetration-testing report (latest)

    The most recent third-party penetration test of the platform.

  • CAIQ security questionnaire

    Pre-completed Consensus Assessments Initiative Questionnaire for self-serve review.

  • Security policies (combined)

    The policies of the written information security program, combined in one document.

  • Security & compliance program update

    Point-in-time summary of the compliance program and what changed.

Procurement paperwork — the W-9 and evidence of insurance — lives in the document library alongside the public policies.

Change notifications

Subprocessor changes carry advance notice: the DPA commits to notifying customers at least ten days before a new subprocessor processes customer personal data, with a written objection right. If an objection cannot be reasonably accommodated, the affected services can be terminated with a pro-rata refund.

Security incidents follow the DPA's breach clause: notice within forty-eight hours once Context judges a suspected personal data breach likely to be confirmed, and notice within seventy-two hours of confirming a breach affecting customer personal data, with the information you need to meet your own notification obligations. A written summary of impact, cause, remediation and preventive actions follows within ten business days of resolution.

Routine program changes — new attestations, refreshed reports, subprocessor-list updates — land in the trust center's updates log. To get them by email, subscribe via security@context.ai.

Roadmap

Planned, not yet shipped

Everything above this line is in place today. Everything below it is committed work that has not shipped yet. We keep the two separate on purpose: a trust center is only useful if a planned control is never dressed up as a present one.

  • SBOM and supply-chain provenance

    Planned

    Signed build provenance and a per-release software bill of materials, so a deployment can verify what it is running against a signature.

    Matters most self-hosted. The SBOM will be requestable in the document library once it ships.

  • Hardened infrastructure images

    Planned

    Minimal, pinned, regularly rebuilt base images for the sandbox and the control plane, shipped identically to managed and self-hosted so a self-hosted install does not drift from what we run.

    Matters most self-hosted. The image inventory will be requestable once published.

  • Crypto-shredding for retention and deletion

    Planned

    Per-tenant key destruction in the managed deployment, so deletion proves the bytes are unreadable rather than unlinking records, and propagates through the backup window.

    For the managed deployment. Self-hosted, retention and deletion are already yours.

  • Prompt-injection detection

    Planned

    Detection for prompt-injection attempts in untrusted content, adding a layer to the egress budget the threat model already spends against.

    Applies across every deployment topology.

These land in the updates log as they ship, and move up into the attestations and controls above once they do.

Request documentation

The document library covers audit reports, assessments, and procurement paperwork. Request what your review needs; anything that requires an NDA is shared once it is in place.

security@context.ai

Also documented: Deployment models · Identity & authorization · Data handling

Request access

Tell us who you are and what your review needs.

Resources