Security posture

Local-first by default. Your provider, your environment.

CutCtx is a local-first control layer for AI-agent traffic. It processes context in your environment and forwards requests to the model provider you configure.

Processing

Your environment

Core proxy and compression workflows run in infrastructure you control.

Egress

Your provider

Requests go to the LLM provider and endpoint selected by your team.

Storage

Your retention

Customer-managed local storage and deployment configuration determine retained operational state.

Understand the boundary

Data flow remains explicit.

CutCtx does not require a hosted prompt analytics service for its core compression workflow.

Data flow

  • Prompt and response content is processed in memory as part of the proxy workflow.
  • Retrieval state, audit records, and identity/organization metadata use customer-managed local storage.
  • You choose the upstream LLM provider and endpoint.
  • CutCtx does not require hosted prompt analytics for its core compression workflow.
Routing safety boundaries

Optimization never bypasses the deployment contract.

Before CutCtx applies an optimization route, it evaluates the request capability contract and the active provider, account, and transport proof.

Capability

Keep required behavior intact.

Requests with tools, structured output, vision, audio, streaming, or other required capabilities stay on the requested model when the selected target cannot prove support.

Transport

Keep the path proven.

Provider, account, and transport safety checks run before routing; a rejected route is retained rather than bypassed.

Evidence

Inspect without changing state.

Read-only routing status and decision evidence explain a safe route or why the requested model remained in place.

Commercial controls

Governance capabilities

Commercial deployments can use SSO/JWT/OIDC admin authentication, role-based access control, audit logging and export, retention controls, fleet-management APIs, and SCIM-style provisioning APIs.

Infrastructure

Deployment choices

Run locally, in Docker or Docker Compose, on Kubernetes, or through an air-gapped deployment path when your environment requires it.

Clear claims

External validation stays external.

Formal certifications and legal agreements require their own review and evidence.

What still requires external validation

Formal certifications, DPAs/MSAs, and third-party audit reports require separate legal, contractual, or independent-review work. This site does not represent them as completed.