Security & Trust

Your team's context. Protected like it matters.

Contextium holds the knowledge your team trusts its AI tools with. This page says exactly how that's protected — what's built, what's documented, and honestly, where we are on certification.

Last updated: 20 July 2026

Your context never trains a model

We never train AI models on your content. Your context is served to the tools you connect — that is its only job.

You decide who and what sees it

Workspace roles gate every teammate; authenticated MCP connections gate every tool. Nothing reads your context by default.

No claims we can't evidence

Every control on this page exists in the product today. Certification status is stated as it is — in progress, not implied.

Security controls

Implemented in the product, evidenced for audit

Data protection

  • AES-256-GCM encryption at rest for stored content
  • TLS encryption for all data in transit
  • API keys SHA-256 hashed with timing-safe comparison — never stored in plain text
  • Passwords hashed with bcrypt; sign-in runs on Microsoft Entra ID
  • Optional Vault storage keeps designated libraries encrypted on-device, off our cloud

Access control

  • Authentication via Microsoft Entra ID, with optional Google and GitHub sign-in
  • Role-based access control: owner, admin, editor, viewer, and guest roles per workspace
  • Workspace-scoped isolation — context is only visible inside its workspace
  • AI tools access context only through authenticated MCP or CLI connections you set up
  • Documented access control and review policy

Auditability

  • Activity audit logging across content, API keys, and workspace operations
  • Every file change is versioned — see who changed what, compare versions, roll back
  • Policy acceptance tracking for terms and privacy updates

Application security

  • Schema validation (zod) on every API request body
  • Rate limiting on all API endpoints
  • Hardened HTTP headers: HSTS, Content-Security-Policy, X-Frame-Options
  • Weekly automated dependency vulnerability scanning (Dependabot)
  • Cloudflare WAF and DDoS protection in front of all traffic

Data lifecycle

  • Account deletion with a 90-day grace period, then permanent removal
  • Documented breach detection & notification runbook (GDPR and CCPA timelines)
  • Documented disaster recovery plan
  • Sub-processor changes notifiable on request via privacy@contextium.io

Compliance, stated honestly

SOC 2 — programme in progress

We are working toward SOC 2 Type I. The documentation phase is complete — information security policy, access control & review policy, breach detection & notification runbook, and disaster recovery plan are all written and maintained — and the technical controls listed above are implemented and evidenced. The remaining step is the formal audit with an AICPA-licensed firm. We'll update this page when that changes; until then we won't put a badge here we haven't earned.

GDPR & CCPA

Data processing agreements are in place with our sub-processors, a published sub-processor list is maintained per GDPR Article 28 (below), and our breach notification runbook covers GDPR and CCPA timelines and contacts. Our Privacy Policy and Terms of Service include GDPR, CCPA, and EU AI Act provisions.

Sub-processors

Every provider that touches customer data — all SOC 2 Type II audited

ProviderPurposeLocationCompliance
Microsoft AzureCloud infrastructure — API, database, runtimeUK South (primary)SOC 2 Type II, ISO 27001
CloudflareCDN, WAF, DDoS protection, file storage (R2)Global CDN; R2 in EUSOC 2 Type II, ISO 27001
StripePayment processing (card details never touch our servers)United StatesSOC 2 Type II, PCI DSS Level 1
ResendTransactional emailUnited StatesSOC 2 Type II
Google / GitHubOptional OAuth sign-in onlyGlobal / United StatesSOC 2 Type II

Request notification of sub-processor changes via privacy@contextium.io

Found a vulnerability?

We take reports seriously and respond quickly. Email security@contextium.io with details and steps to reproduce — we'll acknowledge receipt, keep you updated, and credit you if you'd like.

Frequently asked questions

Is Contextium SOC 2 certified?

Not yet — and we won’t claim otherwise. Our SOC 2 Type I programme is underway: all core policies (information security, access control, breach notification, disaster recovery) are written, and the technical controls are implemented and evidenced. Engaging an AICPA-licensed auditor is the remaining step. Enterprise customers can contact us for current status and documentation.

Is my context used to train AI models?

No. Contextium never trains AI models on your content. Your context is stored, versioned, and served only to the AI tools you explicitly connect — it is your data, delivered to your tools, and nothing else.

Where is my data stored?

Primary infrastructure runs on Microsoft Azure in the UK South region, with uploaded files stored in Cloudflare R2 in the EU. Every sub-processor we use is SOC 2 Type II audited, and the full list is published on this page.

How is my data encrypted?

Content is encrypted at rest with AES-256-GCM and in transit over TLS. API keys are never stored in plain text — they are SHA-256 hashed and verified with timing-safe comparison.

Can I control which AI tools see my context?

Yes. Context is only served to tools you authenticate — via the hosted MCP endpoint, local MCP server, or CLI — and workspace roles (owner, admin, editor, viewer, guest) control what each teammate and their tools can reach. Every change is recorded in the activity log.

One shared context. Every AI tool.

Teach Contextium once — every teammate's AI arrives already briefed.

Set up in minutes • Free plan available • No credit card required