Security review

Security boundaries and current controls

ContextDB uses project-scoped server credentials, tenant isolation, PII-before-embed processing, audit records, encrypted workload stages, and signed backups. This page also names missing controls.

Credential boundary

Credentials

Credential What it is Rules
cdb_ project key Project-wide server credential for the data plane. The key is shown once at creation, stored hashed, and restricted to server-side use. Never place it in a browser, mobile app, or log. Rotation and revocation are control-plane operations. A revoked key fails closed.
cbe_ evaluation token Project-bound server credential for Hosted Alpha Memory CI. The token is shown once, stored hashed, and accepted only by four /evals/v1 operations. It cannot call memory routes or create, read, update, or delete Testbench cases and suites.
user_id A partition key selecting one end-user's memory space. It is not end-user authentication. Your server assigns partitions, and ContextDB enforces the boundary between projects and organizations.
console session Human sign-in for the dashboard. A host-only, Secure, HttpOnly, SameSite=Strict cookie is issued through a server-side BFF. Mutations are CSRF-checked. Project keys never reach JavaScript.

Tenant boundary

Isolation

Orgs, projects, and user partitions are separated by construction and verified by tests that replay observed identifiers across scopes. A project key cannot address another project's data, in the same org or across orgs. Cross-scope resource IDs return 404: existence does not leak.

Content handling

PII posture

PII is detected and encrypted before any embedding call, on every plan. The data plane refuses to start without an encryption key. A missing key is fatal, never a silent downgrade. Memory content, queries, and PII are never written to logs.

Review records

Audit

Only successful, named Cloud events that the service appends enter the organization-scoped SHA-256 hash chain. Current examples include auth.membership.role_changed, project.created, credential.api_key.issued, integration.webhook.created, action.decision.recorded, authorization.memory.confirmed, execution.receipt.recorded, memory.erased, and audit.export.created. Each signed export enumerates its exact event types.

Coverage starts when this feature is deployed, and earlier control-plane activity is not reconstructed. Action decisions and execution receipts append their audit event in the same SQLite transaction as their state change. Several Console control mutations append immediately after their state change and retain a small process-crash gap.

Organization owners can synchronously export up to 10,000 Cloud events in an Ed25519-signed JSON file and verify it with the published public key. SDK memory-operation entries remain in a separate database-global service chain. Hosted read-evidence chaining is also outside this signed Cloud export. A downloaded signature anchors that snapshot. The live chain is not immutable WORM storage, an external transparency log, or a compliance certification.

Hosted workloads

Formation, Memory CI, and source credentials

  • Formation removes PII before the external provider and encrypts request, staged candidate, and terminal result payloads with project/job-bound authenticated data.
  • Formation control columns and usage dimensions omit raw transcripts, prompts, user IDs, candidates, and memory content.
  • Memory CI encrypts suite definitions, case snapshots, comparisons, and summaries. One dedicated single-instance Evals process runs beside the Console API on the same VM and uses PostgreSQL leases, bounded attempts, deadlines, and cooperative cancellation.
  • Memory CI safe status and JSON/JUnit exports omit names, queries, assertion text, raw failures, credentials, and memory content.
  • Managed Source credentials are stored as pinned GCP Secret Manager versions and are not returned by the console after creation.

Recovery evidence

Backup and content-restore verification

  • A daily job quiesces the four write-owning processes and binds the PostgreSQL memory store and SQLite control plane into one signed bundle.
  • The backup bucket enforces public-access prevention, uniform access, bounded lifecycle deletion, soft delete, and a rotating GCP KMS key.
  • A weekly DB-host job verifies signatures, hashes, row counts, and supported audit heads in a disposable PostgreSQL cluster, never over the live database.
  • The first exact bundle passed this drill on August 24, 2026, and both timers were enabled only after the old PG-only cron was disabled.

This is an operated alpha content-restore path. PostgreSQL roles, passwords, grants/ACLs, Secret Manager payloads, PITR, cross-region failover, and complete disaster recovery remain out of band.

Current non-claims

What we do not hold or claim

  • We do not hold a SOC 2 report or any compliance certification today.
  • No BAA is offered today.
  • No uptime SLA, HA topology, region list, RPO/RTO, or latency numbers are claimed or published.
  • The hosted service remains alpha. Nothing here is a compliance posture statement.

Contact

Report a vulnerability

Email gaurav@saaslabs.co with the subject ContextDB security. SDK issues can also be filed at the public tracker.