← Back
Matimo™ Suite of Products Matimo™ Suite of Products

Compliance

Version 2.0  ·  Last updated: 26 July 2026

This page states our compliance posture as it actually stands today. We would rather tell you what we don't have yet than let a vague label do the talking. For our security practices, see Security; for data handling, see our Privacy Notice.

Compliance disclaimer

Matimo™ Enterprise provides tooling and audit evidence to help support SOC 2, HIPAA, and GDPR compliance programs. ROAIQ™ is not itself SOC 2, HIPAA, or GDPR certified, and no such certification is claimed. Using our products does not by itself guarantee compliance with any regulatory framework, compliance remains the responsibility of your organisation.

1. Certification Status

Matimo™ Suite of Products is not currently certified under SOC 2, ISO 27001, or HIPAA, or any other third-party audited compliance framework. Those certifications require a formal audit by an accredited independent auditor, which we have not yet completed. We do not describe ourselves as "SOC 2 compliant," "HIPAA compliant," or similarly certified anywhere in our marketing, and you should treat any such claim about us elsewhere as an error to be reported to support@matimo.ai.

What we do have: internal controls aligned to common control frameworks (access control, audit logging, encryption in transit, tenant isolation, data retention, incident response), described honestly in §2§4 below and in our Security page. Some controls, notably full storage-level (disk) encryption across our database infrastructure, are still being completed as part of ongoing hardening work.

2. Data Protection Alignment

We process personal data in accordance with India's Digital Personal Data Protection Act, 2023. In practice, this means:

  • Self-service data export and account/data erasure (right to be forgotten), available directly from your account settings.
  • Configurable data retention periods, with sensible defaults and a grace period before permanent deletion.
  • Consent-based processing, with a clear path to withdraw consent at any time.
  • A designated contact for data-protection requests and grievances (see §7).

See our Privacy Notice for the full detail behind each of these.

3. Configurable Compliance Posture

Tenant administrators can set a compliance level for their organisation (Basic, GDPR, HIPAA-aligned, or SOC 2-aligned) under Settings. This changes internal platform behaviour, for example stricter audit-log retention, to help you meet your own obligations. Setting a compliance level configures our controls to support that framework; it is not, by itself, a certification that your use of the Platform is compliant with that framework, which depends on how you configure and use the Platform as well.

4. Compliance Evidence Report (Matimo™ Enterprise)

Enterprise tenants can generate a Compliance Supporting Report from Governance settings: an evidence report mapping our actual internal controls against common frameworks (SOC 2, ISO 27001, HIPAA, GDPR, and others), with a per-control drill-down. The report includes a Gaps section and a "Not Verifiable From This System" section for controls that depend on your organisational processes rather than the Platform itself, and can be exported as JSON, CSV, or PDF for your own audit or vendor-review purposes. It is a supporting evidence artifact, not a certification.

5. Sub-Processors & Cross-Border Data Transfer

We use a limited set of sub-processors (cloud infrastructure, LLM providers, email delivery, payments) to operate the Platform, and our infrastructure is currently hosted on AWS in the United States. See §7 and §9 of our Privacy Notice for the full list and our cross-border transfer disclosure.

6. Deployment & Tool Governance Controls

Higher-risk tool connections (for example STDIO-based MCP servers, which run with fewer sandboxing guarantees) are restricted on our shared, multi-tenant deployment. Within your tenant, Human-in-the-Loop approval gating lets you require review before an agent executes a risky tool call, see Security, §6.

7. Requesting Documentation

If you're running a vendor security review and need our Compliance Supporting Report, a completed security questionnaire, or a copy of our sub-processor list ahead of purchase, email support@matimo.ai. For data-protection-specific requests, use privacy@matimo.ai.

8. Changes to This Page

We will update this page as our compliance posture changes, including if and when we complete a formal third-party certification. Material changes will be reflected here with an updated "Last updated" date.

9. Contact

Compliance questions: support@matimo.ai. Data protection: privacy@matimo.ai.