Trust
Security and data
Context Canvas is run by Unicorn Graveyard TM LLC. This page says where your data lives, how it is protected, and how to get it deleted.
Last updated: September 28, 2026
Where data lives
- The check runs in your browser tab. The files you check are never sent to our servers. We record only that a check ran and how many files and findings it had.
- Blueprints, accounts, organizations and the audit log are stored in a PostgreSQL database hosted by Neon. The application runs on Vercel.
- Importing a project sends only Claude Code's config files (
.claude/,.mcp.json,CLAUDE.md,AGENTS.mdand plugin manifests), never your source code.
Encryption
- Every page and API call uses HTTPS, and browsers are told to use nothing else for two years (HSTS).
- Database connections use TLS, and Neon encrypts stored data with AES-256.
- If you connect GitHub, its access token is also encrypted by the application (AES-256-GCM) before it is stored, and is used only to open the pull requests you ask for.
- API keys and invitation links are stored as SHA-256 hashes. Each is shown once, when it is created.
- Sign-in goes through GitHub or Google. Context Canvas never sees or stores a password.
Who can read it
- Every blueprint belongs to one organization, and every query is scoped to it. Asking for another organization's data returns "not found". Automated tests check every API route for this.
- Roles decide who edits, publishes, releases and administers: Owner, Admin, Editor, Approver and Viewer. See governance.
- API keys are read-only and limited to one organization.
Integrity and audit
- Published versions can't be changed: the database rejects updates to them.
- The audit log is append-only. It records who changed, released or exported what, and when. Owners and admins can export it as JSONL or CSV, or read it through the API.
- MCP settings whose values look like credentials are flagged by the build gate, and an organization policy can block them. The API's export preview redacts every
envandheadersvalue.
Retention and deletion
- Data is kept while your account is active.
- Deleting a team organization removes its blueprints, versions and audit log. An owner does it from the organization settings.
- To delete your account, send a privacy request with the email you sign in with. Usage events are then kept without the link to you. The privacy policy has the details.
Reporting a vulnerability
Send a security report through the contact form, not a public issue. Include the steps to reproduce it.