Everything your security team needs.
How Neomatter protects your data, the audit behind it and the companies that help us run it, in one place.
Compliance
SOC 2Type ISOC 2 Type I
Independently audited
SOC 2Type IISOC 2 Type II
In progress
Request the report Get in touch
Policies
Controls
Data protection
- Data is encrypted in transit and at rest.
- Connection tokens are envelope‑encrypted for each organization.
- Your data is never used to train generalized, public or third‑party AI models.
- Model requests run without response storage, and only the content needed for the task is sent.
Access
- Sessions can be revoked at any time.
- Every request is scoped to your organization.
- Neomatter asks for the narrowest permissions that work, and read‑only access where that is enough.
Product security
- Dependency, code and secret scanning run on every change.
- Cross‑tenant access is covered by automated tests.
- Neomatter never sends anything without your permission.
Your data, your control
- Every sensitive read and every change to your data is recorded in an audit log.
- An administrator can export your organization’s data at any time.
- Deleting your organization removes its data and revokes every connection token.
Documents
- SOC 2 Type I reportIndependent audit by a licensed CPA firmRequest
- Security overviewHow Neomatter protects your dataRead
- Privacy policyHow we handle personal dataRead
- Terms of serviceOur commitments to youRead
Subprocessors
The service providers that process customer data on our behalf.
ProviderPurpose
RenderApplication hosting
SupabaseDatabase
VercelWeb hosting
OpenAIAI processing
WorkOSSign-in and authentication
Amazon Web ServicesEncrypted backups and key management
Google CloudEncrypted backups
StripeBilling
GitHubEngineering
AxiomRedacted telemetry
Better StackRedacted telemetry