Trust Center
Everything your security review needs, in one place
Deployment models, controls, policies and subprocessors in one place, with the audit artifacts your security review needs on request.
Audit log
Who granted, shared and revoked access across the organization, and every agent permission decision, with who answered.
| Time (UTC) | Outcome | Event |
|---|---|---|
| Today | ||
| 09:24:51.402 | Recorded | Atlas wrote q3-portfolio-review.pptx · under Q3 portfolio review deck, for Maya Okafor |
| 09:24:48.117 | Blocked | Atlas connected to api.factset.com:443 · not in the allowlist, nothing left |
| 09:24:20.633 | Allowed | Atlas ran python3 build_deck.py --render · approved by Maya Okafor |
| 09:23:58.090 | Asked | Atlas asked to run python3 build_deck.py --render · sent to a person to decide |
| 09:22:31.774 | Allowed | Atlas connected to pypi.org:443 · in the allowlist |
| 09:21:09.255 | Recorded | Atlas read q3-valuation-bridge.xlsx · for Maya Okafor |
| 09:20:44.812 | Recorded | Atlas read q3-portfolio-updates.docx · for Maya Okafor |
| 09:20:02.038 | Recorded | Atlas started a sandbox for Q3 portfolio review deck · for Maya Okafor · record a3f9c2e1 |
Showing 1 to 8 of 8 events
Audit log
Who granted, shared and revoked access across the organization, and every agent permission decision, with who answered.
| Time (UTC) | Outcome | Event |
|---|---|---|
| Today | ||
| 09:24 | Recorded | Atlas wrote q3-portfolio-review.pptx · under Q3 portfolio review deck, for Maya Okafor |
| 09:24 | Blocked | Atlas connected to api.factset.com:443 · not in the allowlist, nothing left |
| 09:24 | Allowed | Atlas ran python3 build_deck.py --render · approved by Maya Okafor |
| 09:23 | Asked | Atlas asked to run python3 build_deck.py --render · sent to a person to decide |
| 09:22 | Allowed | Atlas connected to pypi.org:443 · in the allowlist |
| 09:21 | Recorded | Atlas read q3-valuation-bridge.xlsx · for Maya Okafor |
| 09:20 | Recorded | Atlas read q3-portfolio-updates.docx · for Maya Okafor |
| 09:20 | Recorded | Atlas started a sandbox for Q3 portfolio review deck · for Maya Okafor · record a3f9c2e1 |
Showing 1 to 8 of 8 events
Controls
Security controls
These controls make up the Context security program, covering infrastructure, access, operations, personnel, and data privacy.
Reviewed Aug 2026
Infrastructure security
Encryption in transit
Customer personal data is encrypted in transit using TLS.
Encryption at rest
Customer personal data is encrypted at rest using industry-standard encryption.
Network segmentation and firewalling
Segmentation, firewalling, and hardened configurations hosted with leading cloud providers.
Isolated execution environments
Engine runs each agent in an isolated environment with only the tools configured for its runbook.
Default-deny egress
Sandbox network policy denies egress by default, with allowlists per workflow.
Identity & access
Role-based access control
Logical access controls include role-based access and least-privilege provisioning.
MFA for administrative access
Multi-factor authentication is required for administrative access.
Prompt access revocation
Access is revoked promptly on personnel role change or departure.
SAML, OIDC and SCIM
People sign in with SAML or OIDC, and SCIM 2.0 provisions them.
A key per run
Each run gets its own key, revoked when the run ends, 24 hours at most.
On behalf of the requester
Agents act on behalf of the person who asked; a preset decides what waits for their yes.
Audit log
Each request and decision is a row with its actor, outcome and the person acted for.
Operational security
Vulnerability scanning and patching
Periodic scanning and patching processes are part of the security program.
Third-party penetration testing
The platform is penetration-tested by a third party; the latest report is available on request.
Logging and monitoring
Designed to detect unauthorized access to or use of the services.
Incident response plan
Documented identification, containment, investigation, remediation, and notification.
Business continuity and disaster recovery
Backups and periodic testing of continuity procedures.
Organizational security
Background checks
Performed where permitted by law.
Confidentiality obligations
Personnel are bound by confidentiality obligations.
Security awareness training
Personnel complete security awareness training.
Data & privacy
No cross-customer training
One customer's traces, corrections, and context are not used to train models for other customers.
Run traces stay in your deployment
Trace residency follows the deployment model you select.
Deletion and return of data
At the end of the agreement, customer personal data is deleted or returned at your election.
Breach notification
Notice within forty-eight hours of judging a suspected personal data breach likely to be confirmed, within seventy-two hours of confirming a breach, and a written summary within ten business days of resolution.
Subprocessor agreements and notice
Written flow-down agreements with each subprocessor, and at least ten days' advance notice of new ones.
Start your security review
Anything that requires an NDA is shared once it is in place.

