Security
How Matterhaul protects your data.
Distributors and manufacturers trust Matterhaul with their customer, pricing, and order data. Security is part of how we design, build, and run the product every day, not a checklist we fill out for an audit.
Last updated October 2, 2026
Encrypted everywhere
Data is encrypted in transit and at rest, including backups. Each customer organization’s files and integration credentials are encrypted with their own dedicated key.
Your data stays yours
Every request is scoped to your organization and checked by a permission engine that denies access by default. Your data is used to provide the service to you, and it is not shared with other customers.
Access you control
Manage your team with built-in and custom roles, use multi-factor authentication, and review an audit log of activity in your organization.
Least-privilege operations
Our team reaches production only through single sign-on with MFA, with the least access needed, and that access is logged. Infrastructure is defined in code, and every production change is reviewed before it ships.
Secure development
Every code change is peer-reviewed and tested before release. We automatically scan our dependencies and production systems for known vulnerabilities.
Built to stay up
Matterhaul runs on AWS. Production databases span multiple data centers, and encrypted backups are stored in a separate region. We monitor production around the clock, and we test our incident response and recovery plans every year.
Questions or a report?
Email security@matterhaul.com to request our security documentation or subprocessor list, or to report a vulnerability. We appreciate responsible disclosure and investigate every report we receive.
See also our Terms of Use and Privacy Policy.