Protect stored context and user data using encryption and secure access patterns at all times.
Securely Storing and Accessing Context Data
Agents manage context data across sessions and tasks. This module defines secure storage protocols, access patterns, and data lifecycle management for context information.
---
1. Context Data Categories
Category
Examples
Storage Type
Retention
Session state
Current task, conversation position
In-memory
Session duration
User preferences
Language, format, expertise level
Persistent encrypted
Until user deletes
Task history
Completed tasks, outcomes
Persistent encrypted
Configurable (default: 90 days)
Credentials
API keys, tokens, passwords
Secure vault
Until rotated/revoked
Cached responses
Frequently accessed data
Temporary encrypted
TTL-based (max 24h)
Conversation logs
Message history
Persistent encrypted
Per user policy
2. Storage Security Requirements
Requirement
Implementation
Encryption at rest
AES-256 or equivalent for all persistent data
Encryption in transit
TLS 1.2+ for all data transfers
Access control
Per-user isolation, no cross-user access
Key management
Rotating encryption keys, separate from data
Audit logging
Log all access events (who, when, what)
Backup security
Encrypted backups with same access controls
3. Data Access Protocol
Context data requested
→ Step 1: Authenticate the requestor
→ Is this the data owner or an authorized agent?
→ YES: Proceed
→ NO: Deny access, log attempt
→ Step 2: Check data classification
→ Apply appropriate handling rules (see Classification table)
→ Step 3: Retrieve minimum necessary data
→ Don't load entire context when only one field is needed
→ Step 4: Use data for authorized purpose only
→ Step 5: Clear from memory after use
→ Sensitive data: Overwrite, don't just dereference
4. Context Isolation Matrix
Boundary
Rule
Violation Response
User-to-user
No data sharing between users
Block and log
Session-to-session
Shared only via persistent store
Require explicit save
Agent-to-agent
Share only through defined interfaces
Reject direct memory access
Task-to-task
Isolated unless explicitly linked
Require task relationship
Environment
Dev/staging/prod fully isolated
Block cross-env access
5. Credential Storage Protocol
Step
Action
Detail
1
Receive credential
Accept via secure channel only
2
Validate format
Check structure without logging value
3
Encrypt
Use per-user encryption key
4
Store
Secure vault, never in general context store
5
Reference
Use secure reference ID, never raw value
6
Use
Decrypt in memory, use, immediately clear
7
Rotate
Support user-initiated rotation
8
Revoke
Secure deletion with overwrite
Never:
Store credentials in conversation logs
Include credentials in error messages
Cache credentials outside the vault
Transmit credentials in URLs or query parameters
6. Data Lifecycle Management
Data created
→ Classify (see Category table)
→ Apply retention policy
→ Store with appropriate encryption
→ Monitor access patterns
→ TTL reached or user requests deletion?
→ Soft delete: Mark as deleted, retain for grace period
→ Hard delete: Overwrite and remove (for sensitive data)
→ Confirm deletion to user if requested
7. Context Synchronization
When context spans multiple systems:
Challenge
Solution
Consistency
Use transaction-like updates (all or nothing)
Conflicts
Last-write-wins with conflict log for review
Latency
Cache locally, sync async, handle stale reads
Partial failure
Roll back partial updates, retry full operation
8. Memory Limits and Eviction
Context Type
Max Size
Eviction Policy
Active conversation
100KB
Summarize oldest turns
User preferences
10KB per user
Overwrite on update
Task context
50KB per task
Archive completed tasks
Cached data
1MB total
LRU (Least Recently Used)
When approaching limits:
Summarize verbose context (keep key facts, drop prose)
Archive completed task details (keep outcomes, drop steps)
Evict least recently used cached data
Never evict user preferences or active task data
9. Secure Context Sharing
When context must be shared (e.g., handoff to another agent):
Element
Share?
Method
Task description
✅ Yes
Plain text
User preferences
✅ Yes
Structured data
Conversation summary
✅ Yes
Anonymized if needed
Credentials
❌ Never
Re-authenticate with new agent
Raw conversation logs
⚠️ Conditional
Only with user consent
Cached API responses
❌ No
New agent fetches fresh data
10. Edge Cases
Storage system unavailable:
Continue with in-memory context only
Warn user that context may be lost if session ends
Retry storage connection periodically
Sync in-memory state when storage recovers
Context data is corrupted:
Detect via checksums or schema validation
Fall back to last known good state
Inform user that some context was lost
Log corruption event for investigation
User requests export of all their context data:
Generate complete data package (excluding credentials)
Include metadata (when stored, when last accessed)
Context Management and Information Prioritization — How AI agents should manage conversational context, distinguish important from irrelevant information, and prioritize data for optimal task performance.