Trust & Safety
Context Trust & Safety Center
Security, compliance, and data-handling documentation for the Context platform. Deployment models, certifications, policies, subprocessors, and how to request audit artifacts.
Controls
Security controls
These controls make up the Context security program, covering infrastructure, access, operations, personnel, and data privacy.
Reviewed Aug 2026
Infrastructure security
Encryption in transit
Customer personal data is encrypted in transit using TLS.
Encryption at rest
Customer personal data is encrypted at rest using industry-standard encryption.
Network segmentation and firewalling
Segmentation, firewalling, and hardened configurations hosted with leading cloud providers.
Isolated execution environments
Engine runs each agent in an isolated environment with only the tools configured for its runbook.
Default-deny egress
Sandbox network policy denies egress by default, with allowlists per workflow.
Identity & access
Role-based access control
Logical access controls include role-based access and least-privilege provisioning.
MFA for administrative access
Multi-factor authentication is required for administrative access.
Prompt access revocation
Access is revoked promptly on personnel role change or departure.
IdP-anchored principals
People and agents take identity from your identity provider — Okta and Entra ID.
Short-lived, scoped credentials
Per-task tokens are minted at run time and expire at completion.
Per-action authorization
Policy checks the resource, action, purpose, and approval state before a credential is issued.
Append-only audit trail
Every grant and denial is logged with the identity, task, and rule that decided it.
Operational security
Vulnerability scanning and patching
Periodic scanning and patching processes are part of the security program.
Third-party penetration testing
The platform is penetration-tested by a third party; the latest report is available on request.
Logging and monitoring
Designed to detect unauthorized access to or use of the services.
Incident response plan
Documented identification, containment, investigation, remediation, and notification.
Business continuity and disaster recovery
Backups and periodic testing of continuity procedures.
Organizational security
Background checks
Performed where permitted by law.
Confidentiality obligations
Personnel are bound by confidentiality obligations.
Security awareness training
Personnel complete security awareness training.
Data & privacy
No cross-customer training
One customer's traces, corrections, and context are not used to train models for other customers.
Run traces stay in your deployment
Trace residency follows the deployment model you select.
Deletion and return of data
At the end of the agreement, customer personal data is deleted or returned at your election.
Breach notification
Notification without undue delay after Context becomes aware of a personal data breach.
Subprocessor agreements and notice
Written flow-down agreements with each subprocessor, and at least ten days' advance notice of new ones.