Contextium holds the knowledge your team trusts its AI tools with. This page says exactly how that's protected — what's built, what's documented, and honestly, where we are on certification.
Last updated: 20 July 2026
We never train AI models on your content. Your context is served to the tools you connect — that is its only job.
Workspace roles gate every teammate; authenticated MCP connections gate every tool. Nothing reads your context by default.
Every control on this page exists in the product today. Certification status is stated as it is — in progress, not implied.
Implemented in the product, evidenced for audit
We are working toward SOC 2 Type I. The documentation phase is complete — information security policy, access control & review policy, breach detection & notification runbook, and disaster recovery plan are all written and maintained — and the technical controls listed above are implemented and evidenced. The remaining step is the formal audit with an AICPA-licensed firm. We'll update this page when that changes; until then we won't put a badge here we haven't earned.
Data processing agreements are in place with our sub-processors, a published sub-processor list is maintained per GDPR Article 28 (below), and our breach notification runbook covers GDPR and CCPA timelines and contacts. Our Privacy Policy and Terms of Service include GDPR, CCPA, and EU AI Act provisions.
Every provider that touches customer data — all SOC 2 Type II audited
| Provider | Purpose | Location | Compliance |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure — API, database, runtime | UK South (primary) | SOC 2 Type II, ISO 27001 |
| Cloudflare | CDN, WAF, DDoS protection, file storage (R2) | Global CDN; R2 in EU | SOC 2 Type II, ISO 27001 |
| Stripe | Payment processing (card details never touch our servers) | United States | SOC 2 Type II, PCI DSS Level 1 |
| Resend | Transactional email | United States | SOC 2 Type II |
| Google / GitHub | Optional OAuth sign-in only | Global / United States | SOC 2 Type II |
Request notification of sub-processor changes via privacy@contextium.io
We take reports seriously and respond quickly. Email security@contextium.io with details and steps to reproduce — we'll acknowledge receipt, keep you updated, and credit you if you'd like.
Not yet — and we won’t claim otherwise. Our SOC 2 Type I programme is underway: all core policies (information security, access control, breach notification, disaster recovery) are written, and the technical controls are implemented and evidenced. Engaging an AICPA-licensed auditor is the remaining step. Enterprise customers can contact us for current status and documentation.
No. Contextium never trains AI models on your content. Your context is stored, versioned, and served only to the AI tools you explicitly connect — it is your data, delivered to your tools, and nothing else.
Primary infrastructure runs on Microsoft Azure in the UK South region, with uploaded files stored in Cloudflare R2 in the EU. Every sub-processor we use is SOC 2 Type II audited, and the full list is published on this page.
Content is encrypted at rest with AES-256-GCM and in transit over TLS. API keys are never stored in plain text — they are SHA-256 hashed and verified with timing-safe comparison.
Yes. Context is only served to tools you authenticate — via the hosted MCP endpoint, local MCP server, or CLI — and workspace roles (owner, admin, editor, viewer, guest) control what each teammate and their tools can reach. Every change is recorded in the activity log.
Teach Contextium once — every teammate's AI arrives already briefed.
Set up in minutes • Free plan available • No credit card required