Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
Trust Center

Security and privacy you can hand to your own reviewers

We build compliance tooling, so we hold ourselves to the standards we help you meet. This page sets out how we protect the information you and your team put into PrivMatrix, who we rely on to run the service and how to get the documents your procurement and legal teams will ask for.

Last updated 27 August 2026

How we protect data

Encryption in transit, least-privilege access, passwordless sign-in and optional two-factor for every account.

Who we work with

A short, named list of sub-processors, each vetted and used only to run the service you signed up for.

Documents you can sign

Our Data Processing Agreement is ready to review and counter-sign, and it references this live sub-processor list.

Security

Security practices

The controls that protect your assessment answers, intake and generated packs.

Encryption in transit

All traffic to and from the service runs over TLS (HTTPS). Sign-in links and download links use unguessable, single-purpose tokens.

Least-privilege access

Only the people who need to operate the service can reach production data, and administrative access is role-based and logged.

Passwordless sign-in and 2FA

Customers sign in with a one-time email link, never a reusable password. Any account can add app-based two-factor authentication.

Audit logging

Sign-ins, team changes, security changes and billing actions are recorded in an internal audit trail we can review if a question arises.

Defined retention

We keep each type of data only as long as it is needed, then delete it on a published schedule (see below), not indefinitely.

No advertising trackers

The product does not load third-party advertising or analytics trackers, and it does not sell personal data.

Assurance

Certifications and assurance

A straight answer on where we stand, because you are trusting us with your compliance data.

Where we are today

We are not yet certified to ISO 27001 or SOC 2. We operate the equivalent controls set out on this page - encryption in transit, least-privilege access, audit logging, defined retention and a breach response plan - and we are happy to walk your security team through them.

On our roadmap

Formal ISO 27001 certification is on our roadmap as we grow. We would rather tell you plainly where we are than imply a certificate we do not yet hold.

How our content is built

Our documents are built from primary-source law, market by market. Our methodology page sets out the laws behind each market, the grade system and our currency process.

Reporting a security issue

Found a vulnerability? Email info@privmatrix.com with the details and we will respond promptly. Please give us a reasonable window to fix it before any public disclosure.

Data location

Where your data lives

Hosting location and the legal entity responsible for the service.

Data controller (of the service)
Omegamatrix Software Computer Trading LLC SPC
Registered
Abu Dhabi, United Arab Emirates
Primary hosting region
United Kingdom
Transfer safeguard
Standard contractual clauses where required

When you buy a compliance pack, you are the controller of the personal data inside your own intake answers and we act as your processor to generate the documents. Our Data Processing Agreement sets out that relationship in full.

Sub-processors

Sub-processors

The third parties that help us run PrivMatrix. Each is bound by contract to protect your data and to use it only to provide their service to us. We update this list before adding a new sub-processor.

Sub-processorPurposeData involvedLocation
Cloud hosting providerRuns the application and database that store your account, intake answers and generated packsAccount details, assessment and intake data, generated documentsUnited Kingdom
Transactional email providerDelivers sign-in links, invoices, pack notifications and receiptsName and email address, message contentProvider network
StripeProcesses card payments and issues invoicesBilling name, email, payment details (handled by Stripe, not stored by us)Stripe global infrastructure

The specific hosting and email vendors are named in the signed Data Processing Agreement. To be notified of changes to this list, email info@privmatrix.com and ask to be added to our sub-processor notice list.

Retention

Data retention at a glance

How long we keep each type of data before deletion.

DataKept forThen
Assessment answers and contact detailsUp to 2 years from last activityMarked deleted and removed from working systems
Your generated pack and its download link90 days from creation (live download)Archived for 30 more days for re-issue, then permanently deleted at 120 days
Intake answers behind a paid orderKept with your order so you can review and regenerateDeleted with the order under the limits above
Invoices and payment recordsAs required by tax and accounting lawRetained only for that legal obligation

Full detail, including the legal bases we rely on, is in our Privacy Notice.

Documents

Request our documents

Everything your procurement, security and legal teams typically ask for.

Data Processing Agreement (DPA)

Our standard controller-to-processor DPA, ready to review and counter-sign. Read the DPA →

Privacy Notice and Terms

How we handle personal data and the terms of service. Privacy · Terms

Security questionnaire

Send us your standard questionnaire and we will complete and return it.

This Trust Center describes our current practices and is provided for information. It does not vary the signed agreement between us, which governs if there is any conflict. See also how we build packs.

Part of one platform, not a pile of tools.

Cookie consent, data requests, the Trust Center and monitoring all read from the same compliance core - your markets, your documents and your obligations, defined once and shared across every module.