Security Update
Security Incident Response Statement
What you need to know
- The incident affects the deprecated Context AI Office Suite, our legacy consumer product.
- If you used the AI Office Suite: we will reach out directly to anyone we identify as potentially impacted. You do not need to wait — email security@context.ai with your account email and we will prioritize your inquiry.
- If you are a current Context Bedrock customer: this incident does not affect your deployment, which runs in your own environment.
We are supporting a subset of AI Office Suite users potentially impacted by a recent security incident that we detected and stopped. This incident does not affect Context’s enterprise customers, whose Bedrock deployments run in their own infrastructure. We are publishing this statement to clearly outline what is known today, the actions we have taken, and how we are supporting potentially impacted users.
We know how disruptive incidents like this are for the people affected, and we are committed to being transparent about what happened and how we are responding. We will keep this page updated as we discover more.
Background on the AI Office Suite
In June 2025, we released Context AI Office Suite, a self-serve consumer-targeted workspace designed to help users work with AI agents to build presentations, documents, and spreadsheets. The AI office suite offered a feature that allowed consumer users to enable AI agents to perform actions across their external applications, facilitated via another 3rd-party service.
This feature and entire consumer offering was separate from our current enterprise product, built to run on premises in customer environments.
Our Response to a Security Incident
Last month, we independently identified and stopped a security incident involving unauthorized access to our AWS environment. At the time, we engaged CrowdStrike, a leading forensic firm, conducted an investigation, and informed a customer we identified as impacted. We also closed the AWS environment, hosting service, and associated resources to fully deprecate the consumer product.
Recently, based on information provided by Vercel and additional internal investigation, we learned that OAuth tokens belonging to some AI Office Suite users were compromised during the incident. One of those tokens was used by the attacker to access Vercel’s Google Workspace. Vercel is not a Context customer, but it appears that at least one employee enabled “allow all” on all requested Google Workspace permissions using their Vercel Google Workspace account. These permissions were intended to grant AI agents the ability to perform Google Workspace actions such as writing emails or creating documents on the grantee’s behalf.
We are contacting everyone we have identified as potentially impacted with specific guidance on next steps. We continue to work with CrowdStrike to validate our containment and confirm the full set of affected tokens. Token theft occurred while the AWS environment was still live; that environment and the AI Office Suite’s OAuth application have since been taken down.
We are continuing to verify impact and expect to share further confirmed findings as the investigation progresses. Updates will be posted to this page.
Where we stand
Today, Context serves enterprise customers through an entirely separate platform designed for controlled deployments in customer-owned environments, including air-gapped and on-premise configurations. This current platform is architecturally distinct and fully separated from legacy consumer systems, including the experimental integration referenced above. These implementations are not impacted in this incident.
Following the incident last month, we worked with CrowdStrike to harden our remaining AWS environment — including additional encryption, segmentation, authentication, and monitoring controls — and to strengthen endpoint security and privileged-access controls across the company. We will continue to invest in these controls as the investigation concludes.
Updates
- Apr 21, 2026 · 9:00 AM PTAdded context on the intended functionality behind permission grants.
- Apr 20, 2026 · 6:03 PM PTRevised the Response section with updated findings and containment detail from the ongoing investigation.
- Apr 20, 2026 · 7:06 AM PTAdded a summary and guidance for AI Office Suite users and current Bedrock customers.
- Apr 19, 2026Initial statement published.
Contact
For questions related to this matter, please contact security@context.ai.