NewMatrytech AI Studio is live โ€” build production-grade AI agents in weeks, not quarters.
โ€” Compliance & Security

The answers your security review is going to ask for.

Written plainly, in one place, so a procurement or security team can clear us without a call. If something you need is missing, ask and we will answer in writing โ€” including where the answer is "not yet".

2 business daystypical turnaround on NDAs, DPAs and security questionnaires
100%Source code and IP transfer
Your cloudDeployed into your account by default
NDA ยท DPA ยท MSAWe sign yours, not ours
Named accessTime-boxed, logged, revoked
โ€” How we work with your data

Eight commitments. All of them contractual.

None of this is aspirational. Each item below is something we will put in writing before work starts, and several are the reason engagements clear security review without a meeting.

โ€” 01

You own everything

Full source-code and IP transfer on every engagement โ€” code, infrastructure-as-code, deployment configuration, prompts and evaluation suites. No licence-back, no retained components, no lock-in.

  • Transferred at handover, not on request
  • Includes infrastructure and deploy process
  • You can continue in-house or elsewhere
โ€” 02

Your cloud, your region

We deploy into your AWS, GCP or Azure account by default. Your data stays under your control, your retention policy and your jurisdiction.

  • UK, EU, US or Gulf regions
  • Residency agreed in writing
  • No silent data movement
โ€” 03

Least-privilege access

Production access is granted to named individuals, time-boxed to the work, logged, and revoked at the end. Development runs on synthetic or anonymised data wherever workable.

  • Named individuals, not shared logins
  • Revoked at engagement end
  • We tell you who had access and when
โ€” 04

Encryption as standard

TLS in transit and encryption at rest on everything we build, with database connections refusing unencrypted transport rather than falling back to it.

  • TLS enforced, not merely preferred
  • Encryption at rest by default
  • Secrets in a manager, never in code
โ€” 05

Secure development practice

Dependency scanning, code review before merge, environment separation, and secrets kept out of the repository. Credentials are rotated at handover.

  • Review before merge
  • Separate dev, staging and production
  • Rotation on handover
โ€” 06

Authentication done properly

Password hashing with bcrypt, JSON Web Tokens for session handling, brute-force lockout after repeated failures, and forced credential change on first login.

  • bcrypt hashing, never plaintext
  • Lockout after 6 failed attempts
  • Forced change on first login
โ€” 07

Paperwork without friction

Mutual NDA before a scoping call, a DPA wherever we process personal data, and we work under your MSA rather than insisting on ours.

  • Typically signed within 2 business days
  • Your paper, not ours
  • BAA available where PHI is involved
โ€” 08

Regulated-industry builds

HIPAA, GDPR, UK GDPR and SOC 2 control requirements are routine engineering for us: audit logging, access control, environment separation and documented incident handling.

  • Control mapping available on request
  • BAA where PHI is involved
  • UK data residency available
โ€” Standards

What we build to, stated precisely.

Security reviews get slowed down by vague claims more often than by missing controls. So here is the distinction we hold to, and we would rather lose a week of sales momentum than blur it.

We build systems that meet HIPAA, SOC 2, GDPR and UK GDPR control requirements. That is engineering we do routinely, and we will send you the control mapping for any of them on request.

That is a different statement from holding a certification of our own, and we do not conflate the two. If your procurement process requires a certified vendor, tell us early and we will say plainly whether we qualify rather than discovering it at contract stage.

For engagements involving protected health information we sign a Business Associate Agreement. For personal data of EU or UK residents we sign a Data Processing Agreement and can deploy into UK or EU regions.

โ€” Frequently asked

The questions security teams actually send.

Taken from real questionnaires. If yours asks something not covered here, email info@matrytech.com โ€” a senior engineer answers, not a salesperson.

Who owns the code and the IP?
You do, entirely. Full source-code and intellectual-property transfer is part of every engagement, including infrastructure-as-code, deployment configuration and any prompts or evaluation suites written for an AI build. There is no licence-back, no retained component and no dependency on us to keep running what we built.
Will you sign an NDA, DPA or our MSA?
Yes to all three. We sign mutual NDAs before a scoping call whenever you want one, a Data Processing Agreement wherever we process personal data on your behalf, and we work under your own MSA rather than insisting on our paper. Send the documents to info@matrytech.com and they come back signed or redlined, usually within two business days.
Where does our data live during a project?
In the region you choose. We deploy into your cloud account by default, which means your data stays under your control, your retention policy and your region โ€” the UK, the EU, the US or the Gulf. Where we host on your behalf, the region is agreed in writing before any data moves.
Do your engineers access our production data?
Only when the work requires it, only with named individuals, and only for as long as needed. Development and testing run against synthetic or anonymised data wherever that is workable. Production access is granted per person, time-boxed, logged, and revoked at the end of the engagement โ€” and we will tell you who had access and when.
Can you build to HIPAA or SOC 2 requirements?
Yes โ€” that is a routine part of our work, and it is engineering rather than paperwork. In practice it means audit logging, encryption in transit and at rest, least-privilege access, environment separation, documented incident handling and a Business Associate Agreement where PHI is involved. Note the distinction: we build systems that meet these control requirements, which is different from us holding a certification of our own. Ask us for the control mapping and we will send it.
What happens to our data and access when the project ends?
Access is revoked, credentials we hold are rotated on your side, and any working copies of your data are deleted on a schedule agreed in the contract โ€” with written confirmation when it is done. The handover includes everything needed to run the system without us: code, infrastructure, deployment process and documentation.
How do you handle a security incident?
A named point of contact, notification to you without delay, and a written timeline once the immediate issue is contained. For engagements where it matters we agree the notification window in the contract rather than leaving it to goodwill โ€” 24 or 72 hours depending on your regulatory position.
Which subprocessors do you use?
For our own systems: AWS for hosting, Google Workspace for email, and the model providers named in an AI engagement. On client work we use your accounts wherever possible, so the subprocessor list is yours rather than ours. A current written list is available on request and forms part of the DPA.
โ€” Send us your questionnaire

Clear us before the first call.

Send your security questionnaire, DPA or MSA to info@matrytech.com and it comes back completed or signed, usually within two business days. If there is something we cannot commit to, that will be in the reply too.

Book a 60-min discovery call โ†’
โ€” Founder will reply personally Prakash Singh ยท Matrytech