Trust Center

Everything your security review needs, in one place

Deployment models, controls, policies and subprocessors in one place, with the audit artifacts your security review needs on request.

Audit log

Who granted, shared and revoked access across the organization, and every agent permission decision, with who answered.

All events Atlas Last 30 days
Time (UTC)OutcomeEvent
Today
09:24:51.402RecordedAtlas wrote q3-portfolio-review.pptx · under Q3 portfolio review deck, for Maya Okafor
09:24:48.117BlockedAtlas connected to api.factset.com:443 · not in the allowlist, nothing left
09:24:20.633AllowedAtlas ran python3 build_deck.py --render · approved by Maya Okafor
09:23:58.090AskedAtlas asked to run python3 build_deck.py --render · sent to a person to decide
09:22:31.774AllowedAtlas connected to pypi.org:443 · in the allowlist
09:21:09.255RecordedAtlas read q3-valuation-bridge.xlsx · for Maya Okafor
09:20:44.812RecordedAtlas read q3-portfolio-updates.docx · for Maya Okafor
09:20:02.038RecordedAtlas started a sandbox for Q3 portfolio review deck · for Maya Okafor · record a3f9c2e1

Showing 1 to 8 of 8 events

Audit log

Who granted, shared and revoked access across the organization, and every agent permission decision, with who answered.

All events Atlas
Time (UTC)OutcomeEvent
Today
09:24RecordedAtlas wrote q3-portfolio-review.pptx · under Q3 portfolio review deck, for Maya Okafor
09:24BlockedAtlas connected to api.factset.com:443 · not in the allowlist, nothing left
09:24AllowedAtlas ran python3 build_deck.py --render · approved by Maya Okafor
09:23AskedAtlas asked to run python3 build_deck.py --render · sent to a person to decide
09:22AllowedAtlas connected to pypi.org:443 · in the allowlist
09:21RecordedAtlas read q3-valuation-bridge.xlsx · for Maya Okafor
09:20RecordedAtlas read q3-portfolio-updates.docx · for Maya Okafor
09:20RecordedAtlas started a sandbox for Q3 portfolio review deck · for Maya Okafor · record a3f9c2e1

Showing 1 to 8 of 8 events

Controls

Security controls

These controls make up the Context security program, covering infrastructure, access, operations, personnel, and data privacy.

Reviewed Aug 2026

Infrastructure security

  • Encryption in transit

    Customer personal data is encrypted in transit using TLS.

    DPA, Annex 2 →

  • Encryption at rest

    Customer personal data is encrypted at rest using industry-standard encryption.

    DPA, Annex 2 →

  • Network segmentation and firewalling

    Segmentation, firewalling, and hardened configurations hosted with leading cloud providers.

    DPA, Annex 2 →

  • Isolated execution environments

    Engine runs each agent in an isolated environment with only the tools configured for its runbook.

    Deployment models →

  • Default-deny egress

    Sandbox network policy denies egress by default, with allowlists per workflow.

    Secure VM →

Identity & access

  • Role-based access control

    Logical access controls include role-based access and least-privilege provisioning.

    DPA, Annex 2 →

  • MFA for administrative access

    Multi-factor authentication is required for administrative access.

    DPA, Annex 2 →

  • Prompt access revocation

    Access is revoked promptly on personnel role change or departure.

    DPA, Annex 2 →

  • SAML, OIDC and SCIM

    People sign in with SAML or OIDC, and SCIM 2.0 provisions them.

    Identity & authorization →

  • A key per run

    Each run gets its own key, revoked when the run ends, 24 hours at most.

    Identity & authorization →

  • On behalf of the requester

    Agents act on behalf of the person who asked; a preset decides what waits for their yes.

    Identity & authorization →

  • Audit log

    Each request and decision is a row with its actor, outcome and the person acted for.

    Identity & authorization →

Operational security

  • Vulnerability scanning and patching

    Periodic scanning and patching processes are part of the security program.

    DPA, Annex 2 →

  • Third-party penetration testing

    The platform is penetration-tested by a third party; the latest report is available on request.

    DPA, Annex 2 →

  • Logging and monitoring

    Designed to detect unauthorized access to or use of the services.

    DPA, Annex 2 →

  • Incident response plan

    Documented identification, containment, investigation, remediation, and notification.

    DPA, Annex 2 →

  • Business continuity and disaster recovery

    Backups and periodic testing of continuity procedures.

    DPA, Annex 2 →

Organizational security

  • Background checks

    Performed where permitted by law.

    DPA, Annex 2 →

  • Confidentiality obligations

    Personnel are bound by confidentiality obligations.

    DPA, Annex 2 →

  • Security awareness training

    Personnel complete security awareness training.

    DPA, Annex 2 →

Data & privacy

  • No cross-customer training

    One customer's traces, corrections, and context are not used to train models for other customers.

    Data handling →

  • Run traces stay in your deployment

    Trace residency follows the deployment model you select.

    Data handling →

  • Deletion and return of data

    At the end of the agreement, customer personal data is deleted or returned at your election.

    Data handling →

  • Breach notification

    Notice within forty-eight hours of judging a suspected personal data breach likely to be confirmed, within seventy-two hours of confirming a breach, and a written summary within ten business days of resolution.

    DPA, §8 →

  • Subprocessor agreements and notice

    Written flow-down agreements with each subprocessor, and at least ten days' advance notice of new ones.

    DPA, §6 →

Start your security review

Anything that requires an NDA is shared once it is in place.

Request access

Tell us who you are and what your review needs.

Resources