Security
AMatrix builds production software. Security is part of the product, not an afterthought.
Posture
AMatrix matrices run on sovereign infrastructure under AMatrix control. Inference is not routed to third-party LLM providers by default. Data in transit is encrypted with modern TLS; data at rest is encrypted. Specific controls for a given matrix — encryption keys, audit logging, retention — are confirmed during onboarding.
Responsible disclosure
If you discover a security vulnerability in AMatrix, a matrix, or related infrastructure, we want to hear from you. Report it through the contact page and indicate that your inquiry concerns security.
Please include reproduction steps and, if known, a recommended remediation. We commit to acknowledging a report within 48 hours and providing a remediation timeline within five business days. Coordinated disclosure is standard practice; we offer credit to reporters who follow it.
Compliance
AMatrix is Quebec-based and operates under PIPEDA and Quebec Law 25. Vendor security documentation is available to qualified prospects under NDA — request it through the contact page.