Trust & Safety

Context Trust & Safety Center

Security, compliance, and data-handling documentation for the Context platform. Deployment models, certifications, policies, subprocessors, and how to request audit artifacts.

FAQ

Frequently asked questions

View the full site FAQ →

Deployment

Where does Context run?

Context supports a managed deployment, deployment in a customer VPC, on-premises deployment, and environments designed for disconnected operation. Model endpoints, connectors, the update process, and the support model are configured for the selected architecture.

What data leaves our boundary?

Run traces stay inside your deployment. What crosses the boundary depends on the architecture you select — in a VPC, on-premises, or air-gapped deployment the platform itself runs inside your perimeter. Data-flow boundaries are documented during implementation.

Is it the whole platform inside our perimeter, or just inference?

The entire platform. Context deploys the control plane, execution, and run history — not just model inference — in your VPC, on-premises, or air-gapped.

Security

Do agents hold credentials?

No. Credentials are brokered to the connector at runtime rather than written into the runbook or prompt. Depending on the target system and deployment, the connector can use delegated user identity or a scoped service identity. Credential storage, rotation, and revocation are reviewed as part of the deployment design.

How do agents access our systems?

Engine runs each agent in an isolated environment and gives it only the tools configured for the runbook. Connectors use the authentication method supported by the target system, such as OAuth or a scoped service credential. Read access, write access, and human approval can be configured separately.

What does the audit story look like?

A run records the task, model and tool calls, source references, actions, approvals, and result. Reviewers can inspect the sequence and compare the output with its rubric. Export and retention requirements are configured for the customer's deployment.

How do we get security documentation for a review?

Use the request-access form on this page, or email security@context.ai with what your review needs. Public documents are linked directly; documents that require an NDA are shared once it is in place.

Privacy

Is our data used to train models?

Context does not use one customer's traces, corrections, or institutional context to train models for other customers. Model-provider retention and training settings depend on the endpoints a customer chooses, so those controls are documented and verified during deployment.

Which model providers are involved, and what do they see?

Context is model-agnostic: Claude, GPT, Gemini, Kimi, or open weights. Available endpoints depend on your deployment architecture, and provider retention and training settings are documented and verified during implementation.

Request access

Tell us who you are and what your review needs.

Resources