Trust and security

Security at ContextBridge

ContextBridge maintains a risk-based information security program designed to protect our products, infrastructure, personnel, and customer data.

ContextBridge is committed to protecting the confidentiality, integrity, availability, and privacy of the information entrusted to us. Our security program is supported by documented policies, assigned responsibilities, risk assessments, technical safeguards, personnel controls, incident-management procedures, and business-continuity planning.

Data protection and encryption

We classify information according to its sensitivity and apply safeguards appropriate to that classification. Our policies require confidential customer data to be encrypted at rest and in transit over public networks using strong, industry-standard cryptography.

Access to confidential information is restricted to authorized personnel and systems with a legitimate business need.

For more information about how we handle personal information, see our Privacy Policy and Data Processing Addendum.

Identity and access management

We manage access according to the principles of least privilege and role-based access control. Our access-control program includes:

  • Multi-factor authentication for privileged access to production infrastructure.
  • Documented approval for elevated or non-standard access.
  • Periodic reviews of user, administrator, and service-account access.
  • Prompt adjustment or removal of access when responsibilities change or employment ends.

Secure development and operations

Security is incorporated into our software-development and change-management practices. Our standards require significant changes to be documented, reviewed, tested, and authorized before deployment. Application code is evaluated for security issues, and identified vulnerabilities are prioritized and remediated according to risk.

We use logging, monitoring, alerting, network protections, environment separation, and other operational safeguards to help protect production systems and detect anomalous activity.

Personnel security

Employees and relevant contractors receive security and privacy training appropriate to their responsibilities. Personnel with administrative or privileged technical access are required to complete security-awareness training when they join ContextBridge and at least annually thereafter.

We perform background screening where appropriate, legally permitted, and proportionate to the role and the sensitivity of the information or systems involved. Personnel are also required to acknowledge applicable confidentiality and security responsibilities.

Incident management

We maintain documented procedures for identifying, assessing, containing, investigating, and resolving security incidents. Incidents are documented and reviewed, including root-cause analysis and corrective actions where appropriate.

If an incident requires external notification, ContextBridge coordinates the response with executive leadership and legal counsel and provides notices in accordance with applicable law and contractual commitments.

Business continuity and recovery

Our business-continuity and disaster-recovery program addresses service disruptions, data protection, backup and recovery, communication, escalation, and post-incident review. The program calls for plans and recovery procedures to be reviewed and exercised periodically, with findings used to improve our preparedness.

Third-party risk management

We assess third parties that may access confidential information or affect the security of our services. Reviews consider the nature of the service, the sensitivity of the information involved, and the provider’s relevant security, privacy, availability, and operational controls. Material providers are monitored and reassessed periodically.

Contractual and privacy commitments

Our customer agreements define applicable security, confidentiality, privacy, and service commitments. Additional information is available in our Terms of Service, Privacy Policy, and Data Processing Addendum.

Report a security concern

If you believe you have identified a security issue involving a ContextBridge product or service, contact support@contextbridge.ai with a description of the issue, the affected product or service, and steps that may help us reproduce it.

Please act in good faith and avoid disrupting services, accessing information that does not belong to you, or taking actions that could affect other users.