Trust is the entire game.
MatterOS holds privileged client work, so we treat security as the first rule, not the fine print. This is the plain-English version of how your data is protected - and the standards it is held to.
Held to the standards your clients expect.
MatterOS runs on cloud infrastructure that holds a SOC 2 Type II attestation - independently audited for security, availability, and confidentiality.
We honour the rights of users in the EU and UK under the GDPR: access, correction, portability, and erasure of personal data.
California residents' rights under the CCPA and CPRA are supported, including the right to access and delete personal information.
Processing aligns with India's Digital Personal Data Protection Act, 2023, including consent, purpose limitation, and your rights as a data principal.
SOC 2 Type II refers to the certified cloud infrastructure MatterOS is built on. GDPR, CCPA/CPRA, and the DPDP Act describe the data-protection regimes we align our handling of personal data to. See our Privacy Notice for the full detail.
Four promises, no jargon.
If you read nothing else on this page, read these.
Encrypted, always
Every document, draft, and message is encrypted in transit and at rest. Keys are managed and rotated for you.
Walled off, per firm
Your matters live behind strict per-firm isolation. Only your firm can ever see them; clients see only what you share.
Never trains AI
Your files are processed only for your matters. They are never used to train shared AI models. Full stop.
Always yours
Export your complete record anytime, and delete it for good whenever you want. No lock-in, no hostage data.
Every safeguard, in depth.
Encrypted in transit and at rest
Every document, every transcript, every draft is encrypted in transit (TLS 1.2+) and at rest (AES-256). Keys are managed and rotated.
Every fact traces to a source
Nothing the system asserts exists without a thread back to its origin paragraph. You can verify any line at any time.
Role-based access, scoped by matter
Row-level security in the database enforces that only authorized members of a firm can see a matter, and only the client can see their portal.
Isolated processing
Your documents are processed for your matters only. They are never used to train shared models.
Strong authentication
Google sign-in by default, plus email and password with leaked-password protection. Role-based access controls on every plan.
Honest deletion
Export your data at any time. Delete an account and the matter contents are purged from primary storage, fast and final.
Privilege preserved by design
Your matters, communications, and work product stay inside your firm's walls. Strict tenant isolation, append-only audit logs, and client-portal views you curate, so privileged material is never exposed by default.
AI that shows its work
AI output in MatterOS is labeled, cited back to its source, and never a substitute for your judgment. Nothing is asserted as authority unless it traces to a document on file, and you decide what enters the record.
Your data is portable
Export your firm's full record, matters, parties, chronology, findings, tasks, and the audit log, as structured JSON from Settings at any time. No lock-in, no request tickets.
Every safeguard, on one screen.
Audited, accountable, never opaque.
Every action a person or the system takes inside a matter is recorded. You see what was read, what was proposed, and where every fact came from, and you remain the one who decides what gets committed.
The things lawyers actually ask.
Where is my data stored?+
On cloud infrastructure with SOC 2 Type II attestation, encrypted at rest with AES-256 and in transit with TLS 1.2+. Every firm's data is isolated from every other firm's by row-level security in the database.
Is my client data used to train AI models?+
No. Your documents are processed only for your matters and are never used to train shared AI models. Full stop.
Who can see a matter?+
Only authorized members of your firm, governed by role-based access. The client sees only the portal view you curate and share. Every access is recorded in an append-only audit log.
What happens when I delete a matter or close my account?+
Matter contents are purged from primary storage, fast and final. Encrypted backups age out on a rolling retention cycle. Nothing is held hostage.
Can I get all of my data out?+
Yes. Export your firm's complete record - matters, parties, chronology, findings, tasks, and the audit log - as structured JSON from Settings at any time. No lock-in, no request tickets.
What authentication options are there?+
Google sign-in by default, plus email and password with leaked-password protection, and two-factor authentication. Role-based access controls apply on every plan.
How do you keep the AI honest?+
Every fact MatterOS asserts is cited back to its exact source paragraph, and nothing enters the record until you approve it. Low-confidence legal research is flagged for independent verification, and AI is never a substitute for your judgment.
Have a question we didn't answer here?
We answer every security question from a lawyer ourselves. Bring us the hard one.