Skip to content
Matterwireby Crawlify

Security and trust

Security, trust, and the accuracy SLA

What the 99.5% figure measures, how a record is verified, where your data lives, and exactly where our certifications stand today.

The SLA

99.5%, at the field level.

Most accuracy claims in this category are stated at the document level, where a record counts as correct if it is broadly about the right thing. Ours is measured per field.

A record carries a title, a jurisdiction, an issuing body, a change type, a source URL, a capture timestamp, an effective date and a confidence score. Each of those is a field, and each is scored separately against the source document.

A record whose title is right and whose effective date is wrong counts as a field error. It does not count as a correct record. That is a harder test than the document-level measure, and it is the one the 99.5% figure refers to.

On Enterprise the commitment is written into the contract with a remedy attached. On every plan the measurement runs, and the confidence score and verifier ID travel on the record so you can audit our claim rather than accept it.

  1. 01

    Capture

    The monitor fetches the source document and stores the response with a checksum and a timestamp. The source URL is recorded before anything is read.

  2. 02

    Classify

    AI extracts the fields and classifies the change: new rule, amendment, comment period, effective date. Each classification carries a confidence score.

  3. 03

    Review

    Records below the confidence threshold route to a human verifier. The verifier checks each field against the source text and signs the record with their ID.

  4. 04

    Publish

    The record is released with its source URL, capture timestamp, verifier ID and final confidence score attached. Field-level accuracy runs at 99.5%.

Per-record provenance

The evidence is the record.

Every event between fetch and delivery is logged with an actor and a timestamp, appended as it happens. Entries are append-only: a correction is a new event referencing the original.

Audit trail, record rec_01J8Q4M2X

5 events

  1. captured

    Fetched from federalregister.gov, response 200, checksum stored

    monitor/us-federal

  2. classified

    Change type "amendment", confidence 0.912, below review threshold

    detect/v4

  3. verified

    Fields checked against source text, confidence raised to 0.994

    VER-0148

  4. correlated

    Joined watchlist 'Clean Air' and pipeline 'EHS-Compliance'

    correlate/v2

  5. delivered

    POST to customer endpoint, 202 accepted, delivery id dlv_8f21c

    act/webhook

Data handling

What we hold, and where.

Hosting

AWS. Regulatory source documents are public records. Customer configuration and delivery targets are encrypted in transit and at rest.

What we store about you

Your watchlists, your delivery targets and your users. We do not hold your CRM records or your warehouse contents; we write into them.

Model training

Customer data is never used as training data. Extraction runs against public regulatory source documents.

Access control

Scoped API tokens, signed webhooks, and role-based access with SSO on Enterprise. Access to the evidence store is itself logged.

Privacy and GDPR

Why provenance is a privacy control.

Under GDPR Article 83(5), the most serious infringements are subject to administrative fines up to 20,000,000 EUR, or up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Lower-tier procedural breaches under Article 83(4) cap at 10,000,000 EUR or 2%.

A regulator asking how a control was arrived at is asking a provenance question. Per-record source URLs, capture timestamps and verifier IDs answer it directly. That is the case for building the audit trail into the monitoring rather than bolting it on.

Matterwire is GDPR-aligned. Our processing terms, subprocessor list and data-subject request process are available on request, and the privacy policy sets out what we collect and why.

Compliance roadmap

Where each certification actually stands.

We publish status rather than badges. Nothing below is claimed as complete until the report exists and we can hand you the audit period.

  • GDPR alignment

    Processing terms, subprocessor list and DSR process available on request.

    In place
  • AWS hosting, encryption in transit and at rest

    TLS enforced on all endpoints. Secrets held in a managed vault.

    In place
  • SOC 2 Type II

    Readiness work underway. Report and audit period will be published when the audit completes.

    In progress
  • ISO 27001

    On the roadmap after SOC 2. No certification is claimed today.

    Not started

Security questions that need a specific answer go to security@matterwire.io.

Security questions

What procurement asks first.

Bring your security questionnaire.

Book a demo and we will work through it on the call, including the accuracy methodology and the retention configuration.

No obligation. 30 minutes, on your own jurisdictions.