Last Updated: January 2025
Current State
Architecture
ContextFort currently operates with a local-first architecture:
- Local storage only - No cloud infrastructure
- No data transmission - All data stays on userβs device
- No third party services - Except optional PostHog analytics
- Chrome Extension - Manifest V3 compliant
Compliance Status
| Standard | Status | Notes |
|---|---|---|
| GDPR | β Compliant | No data processing, local storage only |
| CCPA | β Compliant | No sale of personal information |
| SOC2 | π Not Required | No cloud services or data transmission |
| ISO 27001 | π Planned | Q3 2025 for enterprise features |
| HIPAA | β Compliant | No PHI transmission, local storage only |
| PCI DSS | β N/A | No payment processing |
Phase 1: Current (Q1 2025)
Local Extension Only
- Architecture
- Compliance
- Documentation
- Chrome Extension with local storage
- No backend servers
- No data transmission
- Optional analytics (PostHog)
Phase 2: Enterprise Dashboard (Q2-Q3 2025)
Planned Architecture
Required Compliance
SOC2 Type 2 (Q2 2025)
SOC2 Type 2 (Q2 2025)
Scope:
- Security controls
- Availability controls
- Confidentiality controls
- Access controls and authentication
- Encryption in transit (HTTPS/TLS)
- Encryption at rest
- Audit logging
- Incident response plan
- Vendor management
- Third party CPA audit
- Q2 2025: Begin implementation
- Q3 2025: Audit and certification
ISO 27001 (Q3 2025)
ISO 27001 (Q3 2025)
Scope:
- Information security management system
- Risk assessment
- Security controls
- ISMS documentation
- Risk assessment process
- Security policies
- Asset management
- Access control
- Cryptography
- Physical security
- Operations security
- Supplier relationships
- Q2 2025: Gap analysis
- Q3 2025: Implementation
- Q4 2025: Certification audit
Phase 3: Full Compliance (Q4 2025)
Additional Standards
- GDPR (Enhanced)
- ISO 27017 (Cloud Security)
- ISO 27018 (PII in Cloud)
- DPA (Data Processing Agreement) for enterprise
- DPIA (Data Protection Impact Assessment)
- Data transfer mechanisms (if EU customers)
- Right to erasure implementation
- Data portability features
Compliance Features
Current Features
Local Storage
All data stays on userβs device with no transmission required
Chrome Encryption
Chromeβs built-in encryption protects data at rest
Optional Analytics
PostHog can be disabled with one-line configuration change
Open Source
Full code review available for transparency
Planned Features (Q2-Q3 2025)
Encryption in Transit
Encryption in Transit
- TLS 1.3 for all communications
- Certificate pinning
- Perfect forward secrecy
Encryption at Rest
Encryption at Rest
- AES-256 encryption for cloud storage
- Key management system
- Separate encryption keys per tenant
Access Controls
Access Controls
- Role-based access control (RBAC)
- Multi-factor authentication
- Single sign-on (SSO) support
- Audit logging
Data Retention
Data Retention
- Configurable retention policies
- Automatic data deletion
- Backup and recovery
Monitoring & Logging
Monitoring & Logging
- Centralized logging
- Security event monitoring
- Anomaly detection
- Audit trails
Risk Assessment
Current Risks
| Risk | Severity | Mitigation |
|---|---|---|
| Screenshots contain PII | Medium | Local storage only, user controlled |
| No centralized monitoring | Low | Design choice, enterprise phase will address |
| Optional analytics | Low | Can be disabled, no PII transmitted |
Future Risks (Enterprise Phase)
| Risk | Severity | Mitigation Plan |
|---|---|---|
| Data breaches | High | SOC2, encryption, access controls |
| Insider threats | Medium | RBAC, audit logging, least privilege |
| Service availability | Medium | SLA, redundancy, backup |
Third Party Audits
Current
Chrome Web Store
Security review pending
GitHub Dependabot
Automated vulnerability scanning
Community Review
Open source code audit
Planned (Enterprise Phase)
Vendor Management
Current Vendors
| Vendor | Service | Data Access | Compliance |
|---|---|---|---|
| PostHog | Analytics (optional) | Event names only | SOC2, GDPR |
| GitHub | Code hosting | Source code only | SOC2, ISO 27001 |
Future Vendors (Enterprise Phase)
All enterprise vendors will be required to maintain:
- SOC2 Type 2 certification
- ISO 27001 certification
- GDPR compliance
- Regular security audits
- Cloud provider (AWS/GCP/Azure) - SOC2, ISO 27001, PCI DSS
- CDN provider - SOC2, ISO 27001
- Email service - SOC2, GDPR
Enterprise Compliance Support
For enterprise customers, we can provide:
Custom Documentation
Tailored compliance documentation for your organization
Security Questionnaires
Responses to vendor security assessments
Vendor Assessment
Support for your vendor evaluation process
Security Consultation
Direct access to security team