Contexion
  • Product
  • Solutions
  • Pricing
  • About
  • Contact
  • Sign In
Sign In
Enterprise-Grade Security
Last updated · July 28, 2026

Security at Contexion™

How we protect your account, your card data, and the relationships you build on Contexion.ai.

On this page
  1. Our commitment
  2. Infrastructure
  3. Encryption
  4. Access controls
  5. Authentication
  6. Development practices
  7. Monitoring & response
  8. Backups & recovery
  9. Compliance
  10. Data privacy
  11. Reporting a vulnerability
  12. Contact

Our commitment

Contexion stores the contact details, lead records, and relationship signals that drive your pipeline. Protecting that data is foundational to the trust you place in us. This page describes the controls we operate to keep your information secure, available, and private.

What this page covers

These controls apply across all of Contexion™ — contexion.ai (our marketing website), app.contexion.ai (the web application), the Contexion mobile apps for iOS and Android, our APIs and integrations, and the digital cards you publish and share.

Every surface talks to the same hardened backend, so the encryption, access control, monitoring, and incident-response practices below protect your data identically whether you signed in from a browser or a phone. Client-side specifics differ by platform — the web app uses the cookies described in our Cookies Policy, while the mobile apps hold session tokens in the operating system's secure credential storage rather than in cookies.

Infrastructure

Contexion runs on enterprise cloud infrastructure (AWS) in geographically distributed regions. Production servers run in private subnets behind tightly scoped security groups; no production database is reachable from the public internet. We use Cloudflare as our edge network and DDoS protection layer.

Production, staging, and development environments are fully isolated — no shared credentials, no shared databases, no shared accounts.

Encryption

  • In transit: all connections use TLS 1.2 or higher with modern cipher suites. HSTS is enabled on all customer-facing domains.
  • At rest: production databases, object storage, and backups are encrypted with AES-256.
  • Secrets: API keys, OAuth tokens, and integration credentials are encrypted with envelope encryption keys rotated regularly.
  • Credentials: there are no user passwords to store — Contexion is passwordless. One-time sign-in codes are stored only as salted hashes and are destroyed on use or expiry.

Access controls

Internal access to production systems is granted on a least-privilege basis. Every employee request to production data requires:

  • Mandatory hardware-key multi-factor authentication.
  • Single sign-on through our identity provider.
  • Approval through our access review workflow, audited quarterly.
  • Full audit logging of every privileged action.

Access is automatically revoked when an employee's role changes or they leave the company.

Authentication for your account

Contexion is passwordless. You sign in with your email address and a one-time password (OTP) delivered to that address — there is no password to choose, reuse, leak, or reset, and no password database to breach.

  • OTPs are generated with a cryptographically secure random number generator and delivered by our transactional email provider.
  • Each code is valid for 5 minutes and single-use. It is invalidated the moment it is redeemed, when a newer code is requested, or when the 5-minute window elapses.
  • Codes are stored only as salted hashes with an expiry timestamp — never in a readable form.
  • Code requests and failed attempts are rate-limited per email address and per IP to block enumeration, brute-force, and mail-flooding attempts.
  • Session tokens are bound to device fingerprints, rotated regularly, and revoked server-side when you sign out.
  • Suspicious sign-in attempts trigger account-level alerts and automatic challenge.
  • SAML SSO and SCIM provisioning available as an add-on for Team plans and included in Enterprise, so enterprises can enforce their own MFA and lifecycle policies.
  • Authentication events are logged and retained for 12 months for security investigation — see our Privacy Policy.

Because your inbox is the key to your account, we recommend enabling multi-factor authentication with your email provider. Contexion will never ask you for a sign-in code by phone, chat, or support ticket.

Development practices

  • All code changes go through peer review before merging to main.
  • Continuous integration runs automated unit, integration, and security tests on every commit.
  • Static analysis and dependency scanning (CVE checks) on every build.
  • Secrets are never committed to source control; we enforce this with pre-commit hooks and CI scans.
  • We follow OWASP guidelines for web application security.

Monitoring and incident response

Production systems are monitored 24/7 with automated alerting on anomalous traffic, error rates, latency, and authentication failures. We have a documented incident response playbook with severity classifications and notification timelines.

If a security incident affects your account or data, we will notify you without undue delay — and in any case within 72 hours where required by law.

Backups and disaster recovery

Production databases are backed up continuously with point-in-time recovery up to 30 days. Backups are encrypted, stored in a separate region from primary infrastructure, and tested for restorability on a quarterly cadence. Our recovery time objective (RTO) for a regional outage is 4 hours; the recovery point objective (RPO) is 15 minutes.

Compliance

  • SOC 2 Type II — audit in progress. Report available under NDA when complete.
  • GDPR — we operate as a data processor for our customers' lead data and as a data controller for our own customer accounts. Data Processing Agreements available on request.
  • CCPA / CPRA — we honor consumer rights requests and do not sell personal information.
  • ISO 27001 — alignment in progress; certification planned.

Data privacy

For details on what we collect, how we use it, and who we share it with, see our Privacy Policy. For cookies specifically, see our Cookies Policy.

Reporting a vulnerability

If you believe you have found a security vulnerability in Contexion, please report it confidentially to info@contexion.ai with the subject line "Security report". Include reproduction steps and any proof-of-concept code. We commit to:

  • Acknowledging your report within 2 business days.
  • Investigating and responding with our remediation plan within 10 business days.
  • Working with you in good faith on responsible disclosure.
  • Recognizing your contribution publicly (with your permission) once the issue is resolved.

We do not currently operate a formal bug bounty program but treat responsible reports seriously and may offer rewards on a discretionary basis.

Contact

  • Security & privacy questions: info@contexion.ai
  • Enterprise security reviews: sales@contexion.ai
  • Contact form: contexion.ai/contact
Contexion

AI-powered digital business cards and relationship intelligence for professionals and teams.

Product
  • Digital Cards
  • Lead Capture
  • AI Intelligence
  • Integrations
Solutions
  • Sales Teams
  • Recruiters
  • Founders
  • Enterprise
Legal
  • Privacy
  • Terms
  • Security
  • Cookies
Company
  • About
  • Contact Us
© 2026 Contexion™ by Veloxs AI Inc. All rights reserved.