Security review
Security boundaries and current controls
ContextDB uses project-scoped server credentials, tenant isolation, PII-before-embed processing, audit records, encrypted workload stages, and signed backups. This page also names missing controls.
Read the enterprise AI agent memory evaluation guide
This page records current ContextDB controls and gaps. For a vendor-neutral threat model across write, read, act, and delete boundaries, read the AI agent memory security guide.
Credential boundary
Credentials
| Credential | What it is | Rules |
|---|---|---|
| cdb_ project key | Project-wide server credential for the data plane. | The key is shown once at creation, stored hashed, and restricted to server-side use. Never place it in a browser, mobile app, or log. Rotation and revocation are control-plane operations. A revoked key fails closed. |
| cbe_ evaluation token | Project-bound server credential for Hosted Alpha Memory CI. | The token is shown once, stored hashed, and accepted only by
four /evals/v1 operations. It cannot call memory
routes or create, read, update, or delete Testbench cases and
suites. |
| user_id | A partition key selecting one end-user's memory space. | It is not end-user authentication. Your server assigns partitions, and ContextDB enforces the boundary between projects and organizations. |
| console session | Human sign-in for the dashboard. | A host-only, Secure, HttpOnly, SameSite=Strict cookie is issued through a server-side BFF. Mutations are CSRF-checked. Project keys never reach JavaScript. |
Tenant boundary
Isolation
Orgs, projects, and user partitions are separated by construction and verified by tests that replay observed identifiers across scopes. A project key cannot address another project's data, in the same org or across orgs. Cross-scope resource IDs return 404: existence does not leak.
Content handling
PII posture
PII is detected and encrypted before any embedding call, on every plan. The data plane refuses to start without an encryption key. A missing key is fatal, never a silent downgrade. Memory content, queries, and PII are never written to logs.
Review records
Audit
Only successful, named Cloud events that the service appends enter the
organization-scoped SHA-256 hash chain. Current examples include
auth.membership.role_changed,
project.created, credential.api_key.issued,
integration.webhook.created,
action.decision.recorded,
authorization.memory.confirmed,
execution.receipt.recorded, memory.erased,
and audit.export.created. Each signed export enumerates
its exact event types.
Coverage starts when this feature is deployed, and earlier control-plane activity is not reconstructed. Action decisions and execution receipts append their audit event in the same SQLite transaction as their state change. Several Console control mutations append immediately after their state change and retain a small process-crash gap.
Organization owners can synchronously export up to 10,000 Cloud events in an Ed25519-signed JSON file and verify it with the published public key. SDK memory-operation entries remain in a separate database-global service chain. Hosted read-evidence chaining is also outside this signed Cloud export. A downloaded signature anchors that snapshot. The live chain is not immutable WORM storage, an external transparency log, or a compliance certification.
Hosted workloads
Formation, Memory CI, and source credentials
- Formation removes PII before the external provider and encrypts request, staged candidate, and terminal result payloads with project/job-bound authenticated data.
- Formation control columns and usage dimensions omit raw transcripts, prompts, user IDs, candidates, and memory content.
- Memory CI encrypts suite definitions, case snapshots, comparisons, and summaries. One dedicated single-instance Evals process runs beside the Console API on the same VM and uses PostgreSQL leases, bounded attempts, deadlines, and cooperative cancellation.
- Memory CI safe status and JSON/JUnit exports omit names, queries, assertion text, raw failures, credentials, and memory content.
- Managed Source credentials are stored as pinned GCP Secret Manager versions and are not returned by the console after creation.
Recovery evidence
Backup and content-restore verification
- A daily job quiesces the four write-owning processes and binds the PostgreSQL memory store and SQLite control plane into one signed bundle.
- The backup bucket enforces public-access prevention, uniform access, bounded lifecycle deletion, soft delete, and a rotating GCP KMS key.
- A weekly DB-host job verifies signatures, hashes, row counts, and supported audit heads in a disposable PostgreSQL cluster, never over the live database.
- The first exact bundle passed this drill on August 24, 2026, and both timers were enabled only after the old PG-only cron was disabled.
This is an operated alpha content-restore path. PostgreSQL roles, passwords, grants/ACLs, Secret Manager payloads, PITR, cross-region failover, and complete disaster recovery remain out of band.
Current non-claims
What we do not hold or claim
- We do not hold a SOC 2 report or any compliance certification today.
- No BAA is offered today.
- No uptime SLA, HA topology, region list, RPO/RTO, or latency numbers are claimed or published.
- The hosted service remains alpha. Nothing here is a compliance posture statement.
Contact
Report a vulnerability
Email gaurav@saaslabs.co with the
subject ContextDB security. SDK issues can also be filed at
the public tracker.