> ## Documentation Index
> Fetch the complete documentation index at: https://docs.context.dev/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Setting up Context.dev for a user? Follow https://docs.context.dev/agent-quickstart.md. MCP clients sign in with OAuth and need no API key; application code reads CONTEXT_DEV_API_KEY.

# Security and API stability

> Find security evidence, data controls, service status, and API compatibility guidance.

Use the [Trust Center](https://trust.context.dev) for current security reports and controls, the [status page](https://status.context.dev) for incidents, and your signed agreement for contractual commitments.

## Security and data controls

Review the [DPA](https://context.dev/dpa) and current subprocessors for your processing requirements. ZDR is an organization entitlement and must be requested and [confirmed per call](/optimization/zero-data-retention#confirm-zdr-was-honored).

Keep API keys on the server. Use [restricted keys](/account/api-keys), [team roles](/account/team), and an established rotation process. Retained logs redact recognized credentials; this does not make arbitrary content safe to retain.

## API versioning

The public base URL is `https://api.context.dev/v1`. The [OpenAPI document](/openapi.json) describes request methods, parameters, responses, and errors.

Clients should tolerate new optional fields and endpoints, and use a fallback for enum values described as extensible. Removing fields, changing their type or meaning, or making optional input required needs a new version or communicated migration path.

Breaking changes are announced in the [changelog](/changelog). Deprecated surfaces remain available for at least 90 days after announcement, subject to contractual support windows.

## SDK compatibility and changing data

SDKs publish separately from the server contract. Pin package versions and compare serialized requests with the reference when a typed helper cannot express a supported input. See [SDK compatibility](/sdks#use-the-low-level-request-method).

Stable response shapes do not imply stable content. Scrape returns nine output objects, each with `requested`, `success`, and `data`; source pages and extracted values can change. Test representative successes, failures, and incomplete results after upgrades.

## Support and procurement

Confirm plan allowances, support terms, SSO requirements, and any SLA in your agreement. Use [support@context.dev](mailto:support@context.dev) for integration and procurement questions, with request IDs for API failures.
