Security
Security is foundational to Mtrix. This page is a plain summary of the technical and organisational measures we use to protect your data — the practices behind the TOMs referenced by our Data Processing Addendum.
1. Overview
Security isn't something we bolt on — it's how Mtrix is built. This page describes the controls we run. The formal, contractually binding version is the Technical and Organisational Measures (TOMs) referenced by Annex II of our DPA.
Mtrix Inc. operates an all-in-one analytics and experimentation platform that ingests behavioural data on behalf of our customers. Much of that data describes our customers' own end users, so we treat its protection as foundational rather than optional. We have built security into the platform, our infrastructure, and how our team works.
This page is a plain-language summary of the technical and organisational measures we maintain to protect personal data and keep the Services available and resilient. For data we process on a customer's behalf, these measures form the basis of the TOMs incorporated by reference into Annex II of our Data Processing Addendum. Where this page and the DPA differ, the DPA is the binding version and controls. Our use of personal data as a controller is described in our Privacy Policy, and the commercial terms that govern the Services are in our Terms of Service.
Security is a moving target, so we review and improve our controls as the platform, our sub-processors and the threat landscape evolve. We will not materially reduce the overall level of protection we provide. Capitalized terms not defined here have the meaning given in our Terms of Service or DPA.
2. Encryption
Your data is encrypted in transit and at rest, everywhere we hold it.
In transit. All connections between end-user browsers, the Mtrix SDK, our APIs and the dashboard are protected with TLS 1.2 or higher, using modern cipher suites. We serve our application and ingestion endpoints over HTTPS only, enforce HTTP Strict Transport Security (HSTS), and redirect plaintext requests. Certificates are managed and rotated automatically. Traffic between our internal services is likewise encrypted within our network.
At rest. Data stored in our databases, object storage and backups is encrypted using AES-256 or an equivalent strong, industry-standard algorithm. Encryption keys are held in a dedicated key-management service with tightly restricted access and regular rotation; keys are never stored alongside the data they protect. Session recordings and other sensitive payloads a customer chooses to capture are held in isolated, access-restricted storage, as described in section 6 below.
3. Access control & authentication
Least privilege everywhere. Our staff use multi-factor authentication; you can enforce single sign-on for your own team.
Internal access
Access to production systems and to personal data is governed by role-based access control and the principle of least privilege. Personnel are granted only the access their role requires, for a specific purpose, on a need-to-know basis. Access is reviewed periodically and is revoked promptly when someone changes role or leaves. Multi-factor authentication (MFA) is required for staff access to any system that handles personal data, and administrative access takes place over secured, audited channels.
Customer access
Within the dashboard, each Authorized User is assigned a role, and you control your team's permissions through granular access controls scoped to your organisation and projects. Single sign-on (SAML / SSO) is available for applicable plans so you can centralise authentication and provisioning with your own identity provider. We enforce strong credential requirements, and account passwords are stored only as salted hashes — never in plaintext.
Audit logging
Administrative and security-relevant actions are logged. We retain and monitor these logs to support investigations, detect anomalous behaviour, and demonstrate compliance. Customer administrators can review relevant account activity from within the product.
4. Infrastructure & hosting
We host in the EU/EEA by default, separate every customer's data logically, and back everything up with a tested recovery plan.
Hosting and residency. Customer End-User Data and Customer Account Data are hosted and primarily processed in the European Union / EEA. EU data residency is our default. Our infrastructure runs on vetted cloud sub-processors that operate certified data centres with physical access controls, redundant power, and environmental safeguards. Where a sub-processor is located outside the EEA, we rely on the transfer mechanisms described in our DPA (EU Standard Contractual Clauses, the UK IDTA, and the Swiss adaptation, plus adequacy decisions where they exist).
Multi-tenant isolation. Mtrix is a multi-tenant service. Each customer's data is logically separated and access-scoped by organisation and project identifiers, and every request is authorised against the tenant it belongs to, so one customer cannot reach another customer's data.
Isolated storage for sensitive data. Session recordings, any sensitive inputs a customer deliberately chooses to capture, and similar high-sensitivity data are held in isolated, access-restricted storage with stricter access controls than ordinary analytics data.
Backups and disaster recovery. We take regular, encrypted backups and test their integrity. We maintain documented disaster-recovery and business-continuity procedures, with defined recovery objectives, and run redundant infrastructure across multiple availability zones to tolerate the failure of any single component.
5. Application security
Security is part of how we design, review, ship and monitor the product.
We follow a secure software development lifecycle in which security is considered at every stage — design, development, review, deployment and monitoring.
- Code review and change management. Code changes are peer-reviewed before they are merged. We maintain separation between development, staging and production environments, ship through version-controlled CI/CD pipelines with automated checks, and can roll back releases when needed.
- Vulnerability management. We run automated dependency and container scanning together with static analysis, and we track and remediate findings on a risk-prioritised basis. Secrets are kept out of source code and managed through a secrets manager.
- Penetration testing. We engage qualified, independent third parties to perform periodic penetration tests of the platform, and we remediate material findings. Summary results are available to customers under NDA in line with the audit provisions of our DPA.
- Hardening and monitoring. Systems are hardened against common attack classes, and we log and monitor application and infrastructure activity to detect and respond to anomalies.
6. Data protection by design
The product is designed to minimise sensitive data before it ever reaches us — masking runs on the end user's device, not on our servers.
Mtrix is engineered so that the most sensitive data is suppressed at source. By default, the
Mtrix SDK masks the contents of text inputs, form fields and payment fields,
and passwords and fields carrying standard sensitive attributes — for example
type=password and autocomplete=cc-* — are
never captured at all. This suppression happens on the end user's device,
in the browser, before any data leaves it, so Mtrix never receives those
values in the first place.
Customers can tighten or loosen what is captured using CSS-selector blocklists and
allowlists and the data-mtrix-mask and data-mtrix-unmask
attributes. You are responsible for configuring masking appropriately for your site and for
obtaining any consent the law requires. Error and performance payloads —
stack traces and request and response bodies and URLs — are scrubbed for PII by
default.
Retention is configurable. The defaults below are starting points you can change in-product; the binding terms are in section 15 of our DPA and are summarised in our Privacy Policy.
- Session recordings: 30 days by default (customer-configurable, 7–180 days).
- Raw analytics and event data: 24 months by default.
- Heatmap data: derived from events, kept for the same window as events.
- Performance and error telemetry, including stack traces: 90 days by default.
- A/B experiment-assignment data: the duration of the experiment plus 12 months.
Mtrix never sells personal data and never shares it for cross-context behavioural advertising.
7. Compliance & certifications
We align to the EU GDPR, hold SOC 2 Type II and ISO/IEC 27001 certification, and are HIPAA-compliant — we will sign a Business Associate Agreement with eligible customers.
Mtrix is established in Estonia (EU), and we process personal data in line with the EU GDPR as our primary framework, together with the UK GDPR, the Swiss FADP and applicable US state laws where relevant. Our DPA offers the EU Standard Contractual Clauses (Modules Two and Three), the UK International Data Transfer Addendum, and the Swiss adaptation, with EU data residency as the default.
Mtrix maintains SOC 2 Type II and ISO/IEC 27001 certification for its information-security program. Our current SOC 2 Type II report and ISO/IEC 27001 certificate are available to customers and prospects under NDA on request. We are also HIPAA-compliant and will act as a Business Associate under a signed Business Associate Agreement (BAA) for eligible customers — see the HIPAA terms in our DPA. Our full set of technical and organisational measures, and your audit rights, are set out in that DPA.
8. Incident response & breach notification
If a breach affects your data, we investigate, contain it, and notify you without undue delay and within 72 hours of confirming it.
We maintain a documented incident-response plan covering detection, triage, containment, eradication, recovery and post-incident review. Logging and monitoring across our application and infrastructure help us identify potential incidents quickly, and named responders are responsible for driving each incident to resolution.
On confirming a Personal Data Breach affecting Customer End-User Data, we will notify affected customers without undue delay and within 72 hours of that confirmation. Our notice will include the information required by Article 33(3) of the GDPR — the nature of the breach, its likely consequences, and the measures taken or proposed — as that information becomes available, and we will provide reasonable cooperation to help you meet your own obligations to regulators and data subjects. A breach notification is not, by itself, an acknowledgement of fault or liability. The binding terms of this commitment are in section 10 of our DPA.
9. Reporting a vulnerability
Found something? Email security@mtrix.io. We will not pursue legal action against good-faith researchers.
We welcome reports from the security community. If you believe you have found a vulnerability in Mtrix, please email security@mtrix.io with enough detail for us to reproduce and assess the issue. We ask that you practise responsible disclosure:
- Give us a reasonable opportunity to investigate and remediate before any public disclosure.
- Do not access, modify, or delete data that does not belong to you, and only interact with accounts you own or have explicit permission to test.
- Do not degrade, disrupt or overload the Services — no denial-of-service testing, and no spam or social-engineering of our staff or customers.
- Stay within the law, and stop and tell us if you encounter any personal data.
We will acknowledge your report, investigate promptly, and keep you informed of our progress. We will not pursue or support legal action against researchers who act in good faith and within these guidelines. Note that, outside this disclosure channel, unauthorised scanning, probing and penetration testing of the platform are prohibited by our Terms of Service and Acceptable Use Policy.
10. Sub-processors & shared responsibility
We vet every sub-processor and secure the platform. You configure masking, who has access, and consent on your side.
We run the entire Service on Amazon Web Services (AWS), our sole infrastructure sub-processor, and operate every other function — including email delivery, monitoring and support — ourselves rather than through third parties. AWS is bound by data-protection terms and security obligations and hosts your data in the EU. The current sub-processor list, with each provider's purpose and location, is maintained as Annex III of our DPA. We give at least 30 days' advance notice before adding or replacing a sub-processor, and you have a 30-day window to object.
Security is a shared responsibility. The table below summarises what Mtrix secures and what you control as the customer and Controller of your end users' data.
| Mtrix secures | You configure |
|---|---|
| The platform, SDK, APIs and infrastructure, including encryption, multi-tenant isolation and isolated storage for sensitive data. | Which masking, blocklists and allowlists apply on your site, and whether to capture any field as sensitive. |
| Default session-replay masking and PII scrubbing of error and performance payloads. | Who you invite as Authorized Users, the roles you grant them, and whether you enforce SSO. |
| Vulnerability management, secure development, penetration testing and incident response. | Your lawful basis, the notices you give end users, and the consent you collect. |
| Vetting and contracting our sub-processors, and notifying you of changes. | Your retention windows, and not sending Prohibited Data (such as payment card or health data) through the Services. |
11. Learn more
For a plain-language overview of how we keep your data safe, see our Trust & Security page. For the binding detail:
- Data Processing Addendum — the TOMs (Annex II), our sub-processor list (Annex III), international-transfer mechanisms, and the 72-hour breach commitment.
- Privacy Policy — how we handle personal data as an independent controller, and the rights you have over it.
- Terms of Service — the agreement that governs the Services, including liability and governing law.
Questions about our security practices? Email security@mtrix.io.