This page states our compliance posture as it actually stands today. We would rather tell you what we don't have yet than let a vague label do the talking. For our security practices, see Security; for data handling, see our Privacy Notice.
Matimo™ Enterprise provides tooling and audit evidence to help support SOC 2, HIPAA, and GDPR compliance programs. ROAIQ™ is not itself SOC 2, HIPAA, or GDPR certified, and no such certification is claimed. Using our products does not by itself guarantee compliance with any regulatory framework, compliance remains the responsibility of your organisation.
Matimo™ Suite of Products is not currently certified under SOC 2, ISO 27001, or HIPAA, or any other third-party audited compliance framework. Those certifications require a formal audit by an accredited independent auditor, which we have not yet completed. We do not describe ourselves as "SOC 2 compliant," "HIPAA compliant," or similarly certified anywhere in our marketing, and you should treat any such claim about us elsewhere as an error to be reported to support@matimo.ai.
What we do have: internal controls aligned to common control frameworks (access control, audit logging, encryption in transit, tenant isolation, data retention, incident response), described honestly in §2–§4 below and in our Security page. Some controls, notably full storage-level (disk) encryption across our database infrastructure, are still being completed as part of ongoing hardening work.
We process personal data in accordance with India's Digital Personal Data Protection Act, 2023. In practice, this means:
See our Privacy Notice for the full detail behind each of these.
Tenant administrators can set a compliance level for their organisation (Basic, GDPR, HIPAA-aligned, or SOC 2-aligned) under Settings. This changes internal platform behaviour, for example stricter audit-log retention, to help you meet your own obligations. Setting a compliance level configures our controls to support that framework; it is not, by itself, a certification that your use of the Platform is compliant with that framework, which depends on how you configure and use the Platform as well.
Enterprise tenants can generate a Compliance Supporting Report from Governance settings: an evidence report mapping our actual internal controls against common frameworks (SOC 2, ISO 27001, HIPAA, GDPR, and others), with a per-control drill-down. The report includes a Gaps section and a "Not Verifiable From This System" section for controls that depend on your organisational processes rather than the Platform itself, and can be exported as JSON, CSV, or PDF for your own audit or vendor-review purposes. It is a supporting evidence artifact, not a certification.
We use a limited set of sub-processors (cloud infrastructure, LLM providers, email delivery, payments) to operate the Platform, and our infrastructure is currently hosted on AWS in the United States. See §7 and §9 of our Privacy Notice for the full list and our cross-border transfer disclosure.
Higher-risk tool connections (for example STDIO-based MCP servers, which run with fewer sandboxing guarantees) are restricted on our shared, multi-tenant deployment. Within your tenant, Human-in-the-Loop approval gating lets you require review before an agent executes a risky tool call, see Security, §6.
If you're running a vendor security review and need our Compliance Supporting Report, a completed security questionnaire, or a copy of our sub-processor list ahead of purchase, email support@matimo.ai. For data-protection-specific requests, use privacy@matimo.ai.
We will update this page as our compliance posture changes, including if and when we complete a formal third-party certification. Material changes will be reflected here with an updated "Last updated" date.
Compliance questions: support@matimo.ai. Data protection: privacy@matimo.ai.