Security and trust
Security, trust, and the accuracy SLA
What the 99.5% figure measures, how a record is verified, where your data lives, and exactly where our certifications stand today.
99.5%, at the field level.
Most accuracy claims in this category are stated at the document level, where a record counts as correct if it is broadly about the right thing. Ours is measured per field.
A record carries a title, a jurisdiction, an issuing body, a change type, a source URL, a capture timestamp, an effective date and a confidence score. Each of those is a field, and each is scored separately against the source document.
A record whose title is right and whose effective date is wrong counts as a field error. It does not count as a correct record. That is a harder test than the document-level measure, and it is the one the 99.5% figure refers to.
On Enterprise the commitment is written into the contract with a remedy attached. On every plan the measurement runs, and the confidence score and verifier ID travel on the record so you can audit our claim rather than accept it.
- 01
Capture
The monitor fetches the source document and stores the response with a checksum and a timestamp. The source URL is recorded before anything is read.
- 02
Classify
AI extracts the fields and classifies the change: new rule, amendment, comment period, effective date. Each classification carries a confidence score.
- 03
Review
Records below the confidence threshold route to a human verifier. The verifier checks each field against the source text and signs the record with their ID.
- 04
Publish
The record is released with its source URL, capture timestamp, verifier ID and final confidence score attached. Field-level accuracy runs at 99.5%.
The evidence is the record.
Every event between fetch and delivery is logged with an actor and a timestamp, appended as it happens. Entries are append-only: a correction is a new event referencing the original.
Audit trail, record rec_01J8Q4M2X
5 events
- captured
Fetched from federalregister.gov, response 200, checksum stored
monitor/us-federal
- classified
Change type "amendment", confidence 0.912, below review threshold
detect/v4
- verified
Fields checked against source text, confidence raised to 0.994
VER-0148
- correlated
Joined watchlist 'Clean Air' and pipeline 'EHS-Compliance'
correlate/v2
- delivered
POST to customer endpoint, 202 accepted, delivery id dlv_8f21c
act/webhook
What we hold, and where.
Hosting
AWS. Regulatory source documents are public records. Customer configuration and delivery targets are encrypted in transit and at rest.
What we store about you
Your watchlists, your delivery targets and your users. We do not hold your CRM records or your warehouse contents; we write into them.
Model training
Customer data is never used as training data. Extraction runs against public regulatory source documents.
Access control
Scoped API tokens, signed webhooks, and role-based access with SSO on Enterprise. Access to the evidence store is itself logged.
Why provenance is a privacy control.
Under GDPR Article 83(5), the most serious infringements are subject to administrative fines up to 20,000,000 EUR, or up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Lower-tier procedural breaches under Article 83(4) cap at 10,000,000 EUR or 2%.
A regulator asking how a control was arrived at is asking a provenance question. Per-record source URLs, capture timestamps and verifier IDs answer it directly. That is the case for building the audit trail into the monitoring rather than bolting it on.
Matterwire is GDPR-aligned. Our processing terms, subprocessor list and data-subject request process are available on request, and the privacy policy sets out what we collect and why.
Where each certification actually stands.
We publish status rather than badges. Nothing below is claimed as complete until the report exists and we can hand you the audit period.
- In place
GDPR alignment
Processing terms, subprocessor list and DSR process available on request.
- In place
AWS hosting, encryption in transit and at rest
TLS enforced on all endpoints. Secrets held in a managed vault.
- In progress
SOC 2 Type II
Readiness work underway. Report and audit period will be published when the audit completes.
- Not started
ISO 27001
On the roadmap after SOC 2. No certification is claimed today.
Security questions that need a specific answer go to security@matterwire.io.
What procurement asks first.
Bring your security questionnaire.
Book a demo and we will work through it on the call, including the accuracy methodology and the retention configuration.
No obligation. 30 minutes, on your own jurisdictions.
