Skip to content
Contexta

Know Where Your Information Goes.

Contexta holds your skills and company context and delivers them to the AI tools you connect. Your documents stay in your own storage. Here is what we store, who can see it and how we protect it.

Your Documents Stay in Your Storage.

Your knowledge base, such as SOPs, templates, guidelines and scripts, stays in your SharePoint or Google Drive. Skills in Contexta link to the material they need.

Document processing, brand voice and similar tools return a method that your AI applies on your side, so your source files are not uploaded to Contexta in those flows. Your AI works with the documents it can access in its own setup.

What Contexta Stores.

We store what Contexta needs to deliver your skills and run the service.

  • Account and Membership

    Your name, email address, and the organisation, spaces and role you belong to.

  • Skills and Company Context

    The skills, organisation rules, terminology, conventions and space settings your team saves, with their version history.

  • Admin Settings

    The features enabled for your organisation, sign-in domains and related admin settings.

  • Operational Logs

    Records needed to run the service, such as which skill was fetched, when, from which AI product and whether it worked.

  • Billing Details

    For paid plans, your plan, seat count and billing status. Stripe processes payments.

Your AI Provider Processes the Work.

When you use a skill in Claude, ChatGPT, Cursor or another AI product, that provider processes your prompts, your documents and the skill content under its own terms and your settings with it. Contexta’s controls cover the Contexta service itself.

Check your provider’s data and training settings for the plan you use.

Sign-In and Access.

  • No Passwords

    You sign in with your email address and a one-time code. Your AI product connects to Contexta through OAuth, using the same email.

  • Roles

    Members use the organisation’s skills. Editors also create and change your own skills and rules. Admins also manage members, spaces and settings.

  • Groups

    Admins choose which groups get which skills.

  • Sign-In Domains

    Admins choose which email domains can join the organisation, or invite people one at a time.

  • Removing Access

    Removing a member or a sign-in domain stops that path from signing in again. The person should also disconnect Contexta in their AI product.

Isolation and Encryption.

  • Organisation Isolation

    Each request is resolved to your organisation. Other Contexta customers cannot see your skills, rules, members or settings.

  • Encrypted in Transit

    Traffic to and from Contexta uses HTTPS.

  • Encrypted at Rest

    Database storage is encrypted at rest, with Row Level Security on the database.

  • Restricted Production Access

    Access to production systems is authenticated, logged and reviewed.

  • Audit Trails

    Admin and operational changes leave an audit trail. Skill and rule changes are versioned, showing who changed what and when.

The Website Skill Builder.

The skill builder on this website sends what you type or upload, and your answers to its questions, to a third-party AI model provider to create or improve your skill. We keep the result for a short time so you can preview, refine, download or save it. You don’t need an account to use it.

Leave out passwords, API keys, personal information and confidential documents. The Privacy Policy explains how builder input is handled.

The Providers We Use.

We use a small set of providers to run Contexta. Each one is bound by data protection terms appropriate to its role.

Your own AI product is not one of our providers. When you connect Claude, ChatGPT or another AI product, it receives skill content under your own agreement with that provider.

  • Supabase

    Database, sign-in and file storage.

  • Vercel

    Hosting for the Contexta dashboard and connection.

  • Axiom

    Usage and error logs.

  • Google Gemini

    Classifying skills by business function, for coverage reporting.

  • Stripe

    Billing and payments for paid plans.

  • Email Delivery

    Sign-in codes and admin notifications.

  • Skill Builder Model Provider

    Creating and improving skills in the website skill builder.

What We Don’t Offer Yet.

Contexta does not hold SOC 2 or any other formal security certification. Single sign-on (SSO) and automatic user provisioning are not available, and you can’t choose the region where your data is stored.

If your organisation needs any of these, tell us when you get in touch and we’ll explain what is in place today.

Report a Security Issue.

If you find a security vulnerability in Contexta, email security@elab.co.nz. Include what you found, where you found it and the steps to reproduce it. Leave out other people’s data.

Frequently Asked Questions

Does Contexta store my documents?

Your documents stay in your own storage, such as SharePoint or Google Drive. Document processing and similar tools return a method your AI applies on your side, so your source files aren’t uploaded to Contexta in those flows. Contexta stores your skills, company context, account details and the logs needed to run the service. The website skill builder is the exception: it sends the text you type or upload so it can create your skill.

Is Contexta SOC 2 certified?

No. Contexta does not hold SOC 2 or any other formal security certification. This page describes the controls in place today, including sign-in with one-time codes, organisation isolation, encryption in transit and at rest, and audit trails.

Is my content used to train AI models?

We do not use your content to train general-purpose AI models. Your AI provider processes your prompts and documents under its own terms, so check the training settings for your plan with that provider.

Who can access my organisation’s data?

Access is limited to three groups: people in your organisation who sign in with an approved email domain or an invitation, within their Member, Editor or Admin role; the Contexta team who run the platform, under authenticated and reviewed production access; and the providers listed on this page, for the job each one does. Other Contexta customers cannot see your skills, rules, members or settings.

How do I remove someone’s access?

An admin can remove the person from your organisation in the dashboard, or remove a sign-in domain. This stops them signing in again. Ask the person to disconnect Contexta in their AI product’s connector or MCP settings too.

Can we review security requirements before choosing a plan?

Yes. Contact us with your requirements. We’ll explain how the service works today and identify anything that needs a separate discussion.

Ask About Your Requirements.

Tell us about your intended setup and anything your team needs to assess before you connect.