Compliance
Data handling posture for regulated workflows.
ContextBoard is built for teams that process sensitive documents, some of which may contain personally identifiable information (PII) or other regulated data. This page describes our current posture, not a certification -- if you need a specific attestation for a deal, ask on contact sales.
PII / PHI field classification
Extraction schema fields carry an explicit classification (none, PII, or PHI) set by whoever authors the schema. This makes sensitive-field handling visible at the schema level rather than left to be inferred from field names, and lets a workspace apply stricter review or redaction rules to classified fields.
Data residency and retention
Documents and extracted data are stored in your workspace's configured Supabase project. If you need a custom retention window, reach out through contact sales.
Subprocessors
We rely on a small number of subprocessors for infrastructure and model inference. The current list is published on the subprocessor list.
Data processing agreement
Customers requiring a formal data processing agreement can review and execute one -- see Data-processing agreement.
Access control
Access within a workspace follows organization and workspace-level roles, enforced by row-level security at the database layer, described further on the security page.