Trust & Safety

Context Trust & Safety Center

Security, compliance, and data-handling documentation for the Context platform. Deployment models, certifications, policies, subprocessors, and how to request audit artifacts.

Controls

Security controls

These controls make up the Context security program, covering infrastructure, access, operations, personnel, and data privacy.

Reviewed Aug 2026

Infrastructure security

  • Encryption in transit

    Customer personal data is encrypted in transit using TLS.

    DPA, Annex 2

  • Encryption at rest

    Customer personal data is encrypted at rest using industry-standard encryption.

    DPA, Annex 2

  • Network segmentation and firewalling

    Segmentation, firewalling, and hardened configurations hosted with leading cloud providers.

    DPA, Annex 2

  • Isolated execution environments

    Engine runs each agent in an isolated environment with only the tools configured for its runbook.

    Deployment models

  • Default-deny egress

    Sandbox network policy denies egress by default, with allowlists per workflow.

    Agent Sandboxes

Identity & access

  • Role-based access control

    Logical access controls include role-based access and least-privilege provisioning.

    DPA, Annex 2

  • MFA for administrative access

    Multi-factor authentication is required for administrative access.

    DPA, Annex 2

  • Prompt access revocation

    Access is revoked promptly on personnel role change or departure.

    DPA, Annex 2

  • IdP-anchored principals

    People and agents take identity from your identity provider — Okta and Entra ID.

    Identity & authorization

  • Short-lived, scoped credentials

    Per-task tokens are minted at run time and expire at completion.

    Identity & authorization

  • Per-action authorization

    Policy checks the resource, action, purpose, and approval state before a credential is issued.

    Identity & authorization

  • Append-only audit trail

    Every grant and denial is logged with the identity, task, and rule that decided it.

    Identity & authorization

Operational security

  • Vulnerability scanning and patching

    Periodic scanning and patching processes are part of the security program.

    DPA, Annex 2

  • Third-party penetration testing

    The platform is penetration-tested by a third party; the latest report is available on request.

    DPA, Annex 2

  • Logging and monitoring

    Designed to detect unauthorized access to or use of the services.

    DPA, Annex 2

  • Incident response plan

    Documented identification, containment, investigation, remediation, and notification.

    DPA, Annex 2

  • Business continuity and disaster recovery

    Backups and periodic testing of continuity procedures.

    DPA, Annex 2

Organizational security

  • Background checks

    Performed where permitted by law.

    DPA, Annex 2

  • Confidentiality obligations

    Personnel are bound by confidentiality obligations.

    DPA, Annex 2

  • Security awareness training

    Personnel complete security awareness training.

    DPA, Annex 2

Data & privacy

  • No cross-customer training

    One customer's traces, corrections, and context are not used to train models for other customers.

    Data handling

  • Run traces stay in your deployment

    Trace residency follows the deployment model you select.

    Data handling

  • Deletion and return of data

    At the end of the agreement, customer personal data is deleted or returned at your election.

    Data handling

  • Breach notification

    Notification without undue delay after Context becomes aware of a personal data breach.

    DPA, §8

  • Subprocessor agreements and notice

    Written flow-down agreements with each subprocessor, and at least ten days' advance notice of new ones.

    DPA, §6

Request access

Tell us who you are and what your review needs.

Resources