Security and Data Processing
1. Overview
This page summarizes the technical and organizational measures Singular (a Mattom product) takes to protect customer data, and serves as a summary of our Data Processing Addendum (DPA) for business customers. For the full executed DPA, contact sales@mattom.io.
2. Roles and Scope
For GDPR and UK-GDPR purposes, Singular acts as a processor of customer personal data when processing it on a customer's instructions, and as a controller for its own account and administrative data (such as account and billing information). The scope of processing is limited to delivering the Service, securing it, and meeting legal obligations.
3. Data Processing Addendum (DPA)
We offer to execute a DPA with enterprise customers on request. The DPA covers:
- Processing instructions and purposes.
- Sub-processor authorization and notification of changes.
- International transfer mechanisms (Standard Contractual Clauses).
- Confidentiality, security measures, and assistance with data subject requests.
- Audit rights and breach notification timelines.
4. Sub-processors
We use a limited set of approved sub-processors, each with a defined role and location: cloud infrastructure, LLM providers (to which optimized context is routed), self-hosted analytics, transactional email, and payment processing. We notify customers of material changes to this list and provide a way to object where applicable. The list mirrors the sub-processors disclosed in our Privacy Policy.
5. Technical Security Measures
- Encryption in transit: TLS for all connections.
- Encryption at rest: database and object storage encryption.
- Access control: least-privilege, role-based access, with SSO and MFA for staff.
- Secrets management: API keys stored hashed in a managed vault; never returned in
full after creation.
- Logging and monitoring: security event logging with defined retention.
- Network security: isolated networks and firewalling between services.
6. Organizational Security Measures
Our team receives security training, follows an incident-response runbook, and reviews vendors before onboarding. Access to customer data is granted on a need-to-know basis and revoked when no longer required.
7. Data Retention and Deletion
We retain data per the periods described in our Privacy Policy. On contract end, customer content is deleted from active systems within a defined window and purged from backups on the backup cycle. Request metadata is retained for the configured audit period, then deleted.
8. Incident Response and Breach Notification
We monitor for security events and follow a documented incident-response process. If we confirm a security breach affecting customer data, we notify affected customers without undue delay — within 72 hours where feasible under GDPR — through our incident-response channels.
9. Compliance
We are working toward recognized security attestations. We only claim certifications we hold, and we will state the status of any in-progress audit (for example, SOC 2 Type II) with a clear timeline as it advances.
10. Customer Responsibilities
To use the Service securely, customers must protect their API keys, configure access to their account, ensure they have the rights to send the content they process, and notify us of suspected misuse. Customers are responsible for the content they route through the Service.
11. Contact
To report a vulnerability or discuss security, contact us at security@mattom.io. We operate a responsible-disclosure policy and acknowledge reports promptly.