Compliance
The compliance program
Which security artifacts exist for a review, how to request them, and how you hear about changes that affect you.
Attestations
Independent audit reports and attestations are provided on request and as audits complete. For the current status of the compliance program — which reports are available and under what terms — ask security@context.ai.
When a new audit completes, it is added to this page and announced in the updates log.
Requesting audit artifacts
These are the audit artifacts available for a security review. Requests go to the security team with your name, company, and the documents you need; documents that need an NDA go out after it is signed.
The DPA formalizes this: Context makes available the information reasonably necessary to demonstrate compliance, including summaries of third-party audit reports and certifications. Customers also hold a contractual audit right, exercisable once per twelve-month period on thirty days' notice; where adequate, the audit is satisfied by Context's then-current audit reports.
Penetration-testing report (latest)
The most recent third-party penetration test of the platform.
CAIQ security questionnaire
Pre-completed Consensus Assessments Initiative Questionnaire for self-serve review.
Security policies (combined)
The policies of the written information security program, combined in one document.
Security & compliance program update
Point-in-time summary of the compliance program and what changed.
Procurement paperwork — the W-9 and evidence of insurance — lives in the document library alongside the public policies.
Change notifications
Subprocessor changes carry advance notice: the DPA commits to notifying customers at least ten days before a new subprocessor processes customer personal data, with a written objection right. If an objection cannot be reasonably accommodated, the affected services can be terminated with a pro-rata refund.
Security incidents follow the DPA's breach clause: notice within forty-eight hours once Context judges a suspected personal data breach likely to be confirmed, and notice within seventy-two hours of confirming a breach affecting customer personal data, with the information you need to meet your own notification obligations. A written summary of impact, cause, remediation and preventive actions follows within ten business days of resolution.
Routine program changes — new attestations, refreshed reports, subprocessor-list updates — land in the trust center's updates log. To get them by email, subscribe via security@context.ai.
Roadmap
Planned, not yet shipped
Everything above this line is in place today. Everything below it is committed work that has not shipped yet. We keep the two separate on purpose: a trust center is only useful if a planned control is never dressed up as a present one.
SBOM and supply-chain provenance
PlannedSigned build provenance and a per-release software bill of materials, so a deployment can verify what it is running against a signature.
Matters most self-hosted. The SBOM will be requestable in the document library once it ships.
Hardened infrastructure images
PlannedMinimal, pinned, regularly rebuilt base images for the sandbox and the control plane, shipped identically to managed and self-hosted so a self-hosted install does not drift from what we run.
Matters most self-hosted. The image inventory will be requestable once published.
Crypto-shredding for retention and deletion
PlannedPer-tenant key destruction in the managed deployment, so deletion proves the bytes are unreadable rather than unlinking records, and propagates through the backup window.
For the managed deployment. Self-hosted, retention and deletion are already yours.
Prompt-injection detection
PlannedDetection for prompt-injection attempts in untrusted content, adding a layer to the egress budget the threat model already spends against.
Applies across every deployment topology.
These land in the updates log as they ship, and move up into the attestations and controls above once they do.
Request documentation
The document library covers audit reports, assessments, and procurement paperwork. Request what your review needs; anything that requires an NDA is shared once it is in place.
Also documented: Deployment models · Identity & authorization · Data handling