Giant Context
Giant Context
PricingBlog
Get Early Access

Trust and security

Written so you can audit the claims. We are honest about what's built and what isn't. If something is on the roadmap and not shipped, we say so. Hiding the gaps is how trust erodes faster than the gaps themselves.

The short version

Your data is yours. You own it, you can export it in bulk at any time, and you can delete it. We do not train public models on it.

Your data lives on Google Cloud Platform, in the US, with standard encryption in transit and at rest.

AI calls are routed to Google's Gemini models, chosen per job — writing, embeddings, image generation. Google is contracted for no-training commitments on your data.

One person runs this company today. That's the current constraint on how fast we can respond to an incident and how much compliance documentation exists.

We are not enterprise-ready in the formal sense. No SOC 2, no SSO on the base plan, no DPA as a default. All on the roadmap. Ask if you need specifics today.

Subprocessors

The vendors we route your data through to run the product. A list you can read is more useful than one you have to request.

Subprocessor
Purpose
Data touched

Google Cloud Platform

Primary infrastructure — compute, storage, database, analytics (Cloud Run, Cloud SQL, Cloud Storage, BigQuery, Cloud DNS, Memorystore).

All customer data.

Firebase (Google)

Authentication and user session management.

Identity and session data.

Google AI / Vertex AI

AI generation (Gemini models), embeddings, image generation.

Prompts, completions, embedding text, image generation requests.

Resend

Transactional and marketing email delivery.

Recipient email addresses, email subject and body, delivery and engagement events.

Stripe

Billing and payments.

Payment method, billing contact, invoice data.

What we do with your data

You own it

Pages, posts, emails, drafts, KB articles, CRM records, and the context you upload are yours. Export everything in bulk at any time. If you leave, you leave with your data.

No training on your data

Google, the provider we route to, is contracted under terms that prohibit training on customer data. We do not maintain our own foundation model or expose your content to another customer.

Voice via context, not fine-tuning

Your voice lives in retrievable context the AI pulls at generation time. It is not baked into shared weights.

We don't sell data

Not to advertisers, not to data brokers, not to anyone. We retain operation logs scoped to your organization for audit and billing, and we do not mine them across customers. We sell the meter. That's it.

Access, encryption, and where it lives

Your organization owns projects, and only members of your organization can see your content. Roles control what each member can do — read, write, admin, billing — with fine-grained permissions per app and per project. MCP API keys are scoped per organization: a key from one organization cannot reach another's data, and the AI itself cannot cross organizational boundaries.

Internally, engineers have access only to the systems they need, and production data access is logged. We do not read your content, inspect your drafts, or browse your CRM as routine. Jesse has administrative access to production by virtue of running the company; that access is used sparingly and logged. As the company grows, internal access tiers become formal. Today they are small because the company is small.

Encryption is TLS 1.2+ for every request, with public endpoints enforcing HTTPS, and GCP-managed AES-256 at rest for Cloud SQL, Cloud Storage, and BigQuery. Secrets live in Google Secret Manager and rotate on schedule. Data residency is the United States today; EU residency is a roadmap enterprise option and not available now. If you require EU residency today, we are not your tool yet.

Backups run daily across all Cloud SQL databases, with point-in-time recovery inside a 30-day window and per-project JSON and CSV exports on demand. When you delete a project, its content goes to a trash for 30 days, then is hard-deleted. When you delete an organization, all project data and customer records are wiped — hard deletion within 30 days of active systems, and removal from backup rotation within the backup window. There is no clause that retains your data past deletion.

Compliance, honestly

The honest state of play. We'd rather list things as open than invent dates we can't hit.

Not yet. SOC 2 Type I, then Type II, is the first formal compliance program and the priority for the company through the next stretch. The audit process is to begin in the near term, with no date committed. ISO 27001 is planned after SOC 2 Type II.

Not on the base plan today. SSO and SAML are available on request as a flat-priced enterprise add-on, with self-service provisioning on the roadmap. Email plus password, Google, and Microsoft sign-in are supported, with two-factor authentication available.

Not today. Data lives in US GCP regions. EU residency with EU-only data pinning is a planned enterprise option, not shipped. Regional options beyond US and EU are not supported.

No HIPAA and no BAA — we do not support healthcare workloads. No FedRAMP and no government workloads. Payment data is handled entirely by Stripe; we do not touch card numbers directly, so our own PCI scope is minimal by design.

Error monitoring and alerting run on all services, with Jesse on call. A confirmed security incident affecting customer data means direct email to affected customers and a written post-mortem after resolution. There is no formal SLA today — the target is first response within one hour during business hours, and best-effort outside them. One-person on-call means slower response overnight. If you need tighter commitments today, we are not your tool yet.

Email security@giantcontext.com before posting publicly. We acknowledge receipt within two business days, investigate, and fix on a timeline proportional to severity. We'll credit you by name in the post-mortem if you want credit. There is no formal bug bounty program today, but we'll work out something fair case by case.


BuiltUsing MCP
This content was built with MCP using Claude or OpenAI Desktop, LM Studio, Gemini, Codex, or Claude Code MCP. Plain copy, designs, or ideas were submitted to Giant Context and AI finished the job.

A question this page didn't answer?

For a signed subprocessor list, a DPA, a contractual RTO or RPO, or anything a purchase decision hinges on, write to security@giantcontext.com. If we can't commit to it, we'll tell you that instead of inventing a date.

Talk to Jesse
  • How It Works
  • Mind
  • Create
  • Capture
  • Nurture
  • Optimize
  • Publishing
  • Pricing
  • Use Cases

© 2026 Giant Context
Privacy PolicyTermsCookie Policy

Powered by
Trust and Security | Giant Context