Security

How Matterhaul protects your data.

Distributors and manufacturers trust Matterhaul with their customer, pricing, and order data. Security is part of how we design, build, and run the product every day, not a checklist we fill out for an audit.

Last updated October 2, 2026

Encrypted everywhere

Data is encrypted in transit and at rest, including backups. Each customer organization’s files and integration credentials are encrypted with their own dedicated key.

Your data stays yours

Every request is scoped to your organization and checked by a permission engine that denies access by default. Your data is used to provide the service to you, and it is not shared with other customers.

Access you control

Manage your team with built-in and custom roles, use multi-factor authentication, and review an audit log of activity in your organization.

Least-privilege operations

Our team reaches production only through single sign-on with MFA, with the least access needed, and that access is logged. Infrastructure is defined in code, and every production change is reviewed before it ships.

Secure development

Every code change is peer-reviewed and tested before release. We automatically scan our dependencies and production systems for known vulnerabilities.

Built to stay up

Matterhaul runs on AWS. Production databases span multiple data centers, and encrypted backups are stored in a separate region. We monitor production around the clock, and we test our incident response and recovery plans every year.

Questions or a report?

Email security@matterhaul.com to request our security documentation or subprocessor list, or to report a vulnerability. We appreciate responsible disclosure and investigate every report we receive.

See also our Terms of Use and Privacy Policy.