Skip to content
Security

How we protect your work.

What happens to your code and project knowledge, who can reach it, and the controls in your hands. Stated plainly, including what we don’t offer yet.

Last updated

On this page

At a glance

  • A hosted service, clearly bounded.Indexed code and saved knowledge live in ContextStream’s cloud. There is no offline or self-hosted mode today.
  • Secrets filtered before upload.Ignore rules, environment files, keys, and certificates are excluded before anything is indexed.
  • Workspaces are the boundary.Roles decide who can read, contribute, or administer. Personal records stay personal.
  • Encrypted in transit.Traffic between your tools and ContextStream uses TLS, and connected-service tokens are encrypted before storage.

How your data flows

ContextStream is a hosted service. When you index a repository, a small helper on your machine validates the checkout and sends eligible files to ContextStream, where they are stored to build your search index. Decisions, lessons, documents, and other records your assistant saves are stored the same way.

Running the connection locally changes how your editor reaches us, not where search and memory live. If a repository must never leave your machine, don’t index it.

What stays out of the index

Before anything is uploaded, the indexer skips:

  • files matched by your Git ignore rules and a .contextignore file;
  • secret-looking files, environment files, certificates, private keys, and known credential folders;
  • binary and media files, unless you choose to add supported media;
  • files larger than 5 MB.

Local checkout paths and credentials embedded in Git remote URLs are also removed from project metadata. These filters are a safety net, not a substitute for keeping secrets out of your repository. If a secret is ever indexed, rotate it first, then remove the file.

Access and permissions

A workspace is the security boundary for your data. Owners and admins manage the workspace and billing, members read and contribute, and viewers have read-only access. Personal records are visible only to their owner, and on Team plans conversation transcripts are personal by default.

Working with a client whose material must stay separate? Give it its own workspace. And ContextStream never widens what your connected assistant is allowed to do; you stay in control of consequential actions.

Sharing with capsules

A capsule shares selected context without opening the rest of the workspace. You choose the audience, redaction level, expiry, and use limit; external links start with conservative defaults. You can preview what the recipient will see, review the share’s audit trail, and revoke it at any time. Revocation takes effect immediately.

Encryption and infrastructure

Traffic between your tools and ContextStream is encrypted with TLS 1.2 or later. Access tokens for services you connect are encrypted by the application before they are stored. ContextStream runs on OVHcloud infrastructure with Cloudflare in front of it.

AI providers

Search uses service providers to process the content you index. When a feature or managed agent generates an answer, the context it needs is sent to a language-model provider. If you bring your own model key, those requests follow your provider’s terms.

We don’t use your project data to train AI models. Optional deep project learning requires audited consent, stays in your authorized account and project scope, and uses service-managed providers under no-training terms. Withdrawal stops collection immediately and queues deletion within 30 days. Read more in our privacy policy.

Transcript capture

Editors connected by our setup save conversation transcripts by default, so your assistant can pick up where you left off. To turn capture off for connected editors, run:

  • contextstream-mcp configure --transcripts off
  • contextstream-mcp configure --hook-transcripts off

Your assistant may keep its own history separately; its settings govern that.

Service status

Our public status page shows live health for the API, MCP gateway, dashboard, sign-in, and search and memory, refreshed every 30 seconds.

What we don’t offer yet

We’d rather tell you now than in a procurement review. Today, ContextStream doesn’t offer self-hosted, VPC, or offline deployment, customer-managed encryption keys, or audit-log export to a SIEM, and we don’t hold a SOC 2 or ISO 27001 certification. If any of these matter for your rollout, tell us; we’re glad to answer security questionnaires.

Reporting a vulnerability

If you believe you’ve found a security issue, email [email protected] with the details and steps to reproduce. Please give us up to 90 days to investigate and fix it before disclosing it publicly. We appreciate responsible reports.

Questions from your security team?

We’re happy to walk through architecture, data handling, and questionnaires with you.