Skip to content
Book a demo

Everything your security team needs.

How Neomatter protects your data, the audit behind it and the companies that help us run it, in one place.

Compliance

SOC 2 Type I

Independently audited

SOC 2 Type II

In progress

Request the report

Controls

Data protection

  • Data is encrypted in transit and at rest.
  • Connection tokens are envelope‑encrypted for each organization.
  • Your data is never used to train generalized, public or third‑party AI models.
  • Model requests run without response storage, and only the content needed for the task is sent.

Access

  • Sessions can be revoked at any time.
  • Every request is scoped to your organization.
  • Neomatter asks for the narrowest permissions that work, and read‑only access where that is enough.

Product security

  • Dependency, code and secret scanning run on every change.
  • Cross‑tenant access is covered by automated tests.
  • Neomatter never sends anything without your permission.

Your data, your control

  • Every sensitive read and every change to your data is recorded in an audit log.
  • An administrator can export your organization’s data at any time.
  • Deleting your organization removes its data and revokes every connection token.

Documents

Subprocessors

The service providers that process customer data on our behalf.

ProviderPurpose
RenderApplication hosting
SupabaseDatabase
VercelWeb hosting
OpenAIAI processing
WorkOSSign-in and authentication
Amazon Web ServicesEncrypted backups and key management
Google CloudEncrypted backups
StripeBilling
GitHubEngineering
AxiomRedacted telemetry
Better StackRedacted telemetry

Anything else?

Send a questionnaire or report an issue.

Email security