Academy Essay

Your AI Vendor Can Read Everything. Ours Has to Ask.

July 28, 2026 · updated October 6, 2026

Every hosted AI vendor can reach your data. What matters is what is separated by design, what is policy, and whether you can see it. Here is ours.

Every AI vendor’s security page says roughly the same thing: encryption, certifications, access controls, “we take your privacy seriously.” Read carefully and you will notice what none of them say plainly: the people who run this service can reach your data. It is true of almost every hosted product, because somebody has to run the machines, fix the bugs and answer the support tickets. The protection between those people and your content is mostly policy: rules about who should not look, and when.

Policy is better than nothing. But a rule you cannot see is a promise, and promises have exceptions, bad days, subpoenas and breaches. The useful questions are narrower than “is my data safe”: which boundaries are built into the system, which are rules, and which of the rules can you watch being kept?

An earlier version of this essay was titled “Ours Cannot.” It described a product we no longer sell: an engine installed on infrastructure the customer owned, with backups sealed to a key only the customer held. Context Engine is now a hosted service, one memory that ChatGPT, Claude, Claude Code and Cursor read from and save to. For a hosted service, “we cannot read your data” would not be true, so we will not say it. What follows is what we can say, sorted honestly into architecture and policy.

Architecture: your engine is not a row in someone else’s table

In Context Engine your memory lives in engines: one for you, one per client or project, one for a team. Every engine gets its own database, its own search index and its own Worker on Cloudflare. Isolation between engines is physical, not a filter on a shared table.

That matters because the most common way customer data leaks in multi-tenant software is not a malicious employee. It is a query that forgot its filter, a cache keyed slightly wrong, a search that returned the neighbour’s results. When the database another customer’s memories live in is not attached to the process answering your request, a bug of that kind has nothing to return. And across engines, even a memory’s title and its engine’s name are shown only to someone who can reach that engine.

Be precise about what this protects against: other customers, and mistakes in shared code. It does not, by itself, protect you from us. We run the platform those databases live on. That is the part that needs a rule, so it gets one, and you get to watch it.

Policy you can watch: support has to ask

Context Engine support opens an engine only when an owner or admin approves a request, for the time the request names, and every visit is logged. The request waits on the engine’s security settings and on Home, saying who is asking, why, what they could do and for how long, with Approve and Decline. Under it is the visit log.

There is one exception, and we would rather you read it here than find it later. When we have a legal or safety duty to open an engine, it opens at once, the owner is told at once, and the visit is logged like any other. Every vendor has that exception, because a court order or a credible threat to someone’s safety does not wait for approval. Most leave it unwritten. We put it in writing because an exception that is stated, announced and logged is one you can hold us to.

This is policy, enforced in software we operate. We are not going to dress it up as mathematics. Its strength is that it is specific and visible: you know who asked, you decided, and the log says what happened. A rule that leaves a record you can read is a different thing from a rule you are asked to take on faith.

What happens to the content itself

Your content is sent to models only to answer you. It is never used to train a model, it is not sold, and it is not used for advertising.

One boundary deserves candour because it is not ours. When ChatGPT or Claude reads a memory from your engine, that memory is now part of a conversation in their product, under their terms. Context Engine controls what each connection may reach: every connection reaches only the engines you tick, each at Can read or Can read and save, a viewer’s connections only read, and an owner or admin sees every connection reaching their engine, with its access and last use, and can cut it off. What the AI tool’s own vendor does with a conversation is a question for that vendor. Ask them the same questions you are asking us.

Leaving is a download

The final test of “your data is yours” is what happens when you go. Export gives you one ZIP of Markdown and JSON that opens without us. Every memory is a Markdown file with YAML frontmatter, so a text editor works, grep works, and any notes app that reads the format opens it. An illustrative memory, as exported:

---
type: decision
title: Retainer moves to quarterly billing
rationale: Monthly invoices were costing the client's finance
  team a week of approvals each cycle.
decided_at: 2026-09-12
---
Agreed on the 12 September call. Starts with the Q4 invoice.

An export can be restored into an empty engine, which is also how you would move an engine to another region. Deleting an engine is scheduled a day ahead, so you can take that export; then it is gone, with its database, search index and stored files.

Where it lives, stated exactly

If you choose the EU when you create an engine, its database and stored files are kept in the EU. That is the whole claim. We do not claim EU residency for the search index or for the models that answer you, and you should be wary of any vendor whose residency claim is broader than the parts it can name.

For teams, an engine can require your company’s single sign-on (OpenID Connect: Okta, Entra ID, Google’s directory) and two-step sign-in, and removing someone at your identity provider ends their access and their AI tools’ access.

Architecture versus policy, side by side

QuestionTypical hosted AI toolContext Engine
Is your data separated from other customers’?Usually by a filter on shared tablesOwn database, search index and Worker per engine
Can the vendor’s staff open your content?Yes, restricted by internal policyOnly on an owner’s or admin’s approval, for a stated time, logged
ExceptionsUsually unstatedLegal or safety duty: opens at once, owner told at once, logged
Training on your contentVaries, often opt-outNever
LeavingExport, sometimesOne ZIP of Markdown and JSON that opens without us
Data locationOften unspecifiedEU option for database and stored files, and only those

Why we sorted it this way

A hosted service is trust plus controls. Anyone who tells you it is mathematical impossibility is selling the adjective. What a vendor can honestly offer is three things: the boundaries that really are architecture, built as architecture; the rules that remain, made specific, visible and logged; and an exit cheap enough that you are never staying because leaving is hard.

We would rather compete on that sorting than on the word “secure.” If your clients’ confidentiality is what your business actually sells, ask every AI vendor you use the questions from our ownership checklist: who can open our content, under what approval, and where would we see that they did? Ask for the mechanism, not the certification.

Our answers are above. The plans are on pricing, and you can start free and check them for yourself.