Who owns the code and the IP?
You do, entirely. Full source-code and intellectual-property transfer is part of every engagement, including infrastructure-as-code, deployment configuration and any prompts or evaluation suites written for an AI build. There is no licence-back, no retained component and no dependency on us to keep running what we built.
Will you sign an NDA, DPA or our MSA?
Yes to all three. We sign mutual NDAs before a scoping call whenever you want one, a Data Processing Agreement wherever we process personal data on your behalf, and we work under your own MSA rather than insisting on our paper. Send the documents to info@matrytech.com and they come back signed or redlined, usually within two business days.
Where does our data live during a project?
In the region you choose. We deploy into your cloud account by default, which means your data stays under your control, your retention policy and your region โ the UK, the EU, the US or the Gulf. Where we host on your behalf, the region is agreed in writing before any data moves.
Do your engineers access our production data?
Only when the work requires it, only with named individuals, and only for as long as needed. Development and testing run against synthetic or anonymised data wherever that is workable. Production access is granted per person, time-boxed, logged, and revoked at the end of the engagement โ and we will tell you who had access and when.
Can you build to HIPAA or SOC 2 requirements?
Yes โ that is a routine part of our work, and it is engineering rather than paperwork. In practice it means audit logging, encryption in transit and at rest, least-privilege access, environment separation, documented incident handling and a Business Associate Agreement where PHI is involved. Note the distinction: we build systems that meet these control requirements, which is different from us holding a certification of our own. Ask us for the control mapping and we will send it.
What happens to our data and access when the project ends?
Access is revoked, credentials we hold are rotated on your side, and any working copies of your data are deleted on a schedule agreed in the contract โ with written confirmation when it is done. The handover includes everything needed to run the system without us: code, infrastructure, deployment process and documentation.
How do you handle a security incident?
A named point of contact, notification to you without delay, and a written timeline once the immediate issue is contained. For engagements where it matters we agree the notification window in the contract rather than leaving it to goodwill โ 24 or 72 hours depending on your regulatory position.
Which subprocessors do you use?
For our own systems: AWS for hosting, Google Workspace for email, and the model providers named in an AI engagement. On client work we use your accounts wherever possible, so the subprocessor list is yours rather than ours. A current written list is available on request and forms part of the DPA.