Security & Single-Tenant Deployment
Matterfact runs as a single-tenant deployment in an isolated cloud: your private files indexed inside the boundary, default-deny egress, governed MCP connectors, and a full audit trail.
URL: https://www.matterfact.com/security Book a demo: https://www.matterfact.com/?utm_source=llm&utm_medium=markdown&utm_campaign=security Last updated: 2026-09-08
Why this page exists
The work a fund does is sensitive by design. Pipeline, research notes, and IC memos belong inside a clear boundary, and most AI tools ask you to move them outside one. Matterfact is built the other way round: each fund gets its own isolated environment, and the controls are enforced by the deployment rather than promised in a policy document.
The four guarantees
1. Your documents, fully integrated
Research notes, IC memos, internal models, and expert call transcripts are indexed and searchable inside the boundary, with citations back to the sources Matterfact used. Your files stay within the tenant and are never used to train models.
2. Single tenant deployment
A dedicated environment provisioned for your fund alone: isolated compute, isolated storage, isolated vector indexes, and isolated logs. There is no shared tenant, no co-mingled embeddings, and no other fund inside the deployment.
3. Default-deny outbound
Nothing leaves the environment unless you allow it. Your team approves the model endpoints and data sources Matterfact can reach, and every outbound call is logged for review.
4. Connectors on an allowlist
Tools and MCP connectors run inside your tenant, from a reviewed allowlist, with scoped credentials per tool. No arbitrary third-party servers, no silent tool additions, and no connector your team has not approved.
What sits inside the boundary
- Watchlists, pipeline, and idea lists
- Research notes, IC memos, and internal models
- Expert call transcripts and email
- Every prompt and every answer
- Embeddings, indexes, and caches
What stays under your control
- Which model endpoints are reachable
- Bring your own API keys for model providers, so model usage runs under accounts your fund holds directly
- Which connectors and MCP servers are enabled
- Who can access what, via SSO and role-based access control
- Retention windows and deletion
- Audit log export to your SIEM
The security checklist
The controls your security team asks about are in place before the first call, with evidence to back them:
- SOC 2 Type II, independently audited
- Third-party penetration testing
- SSO and SAML with role-based access control
- TLS 1.3 in transit, encrypted at rest
- Strict key rotation policies
- An exportable audit log of queries, sources, and outbound calls
- DDQ and vendor security review support under NDA
Deployment options
Matterfact runs single tenant in every configuration. The choice is where that tenant lives:
| Option | Where it runs | Typical fit |
|---|---|---|
| Matterfact-hosted | An isolated environment on AWS or Google Cloud, dedicated to your fund | Most funds |
| Customer VPC | Inside your own cloud account and network | Firms with stricter network requirements |
| On-premise | Your own infrastructure | Firms that cannot use public cloud for this workload |
In a customer-hosted deployment you control where content is stored and processed, and Matterfact does not host your content outside that environment except for support artifacts you provide.
Systems Matterfact connects to
Snowflake, SharePoint, OneDrive, Outlook, Notion, and Google Drive, each through a connector your team enables explicitly and scoped with least-privilege credentials.
Frequently asked questions
Is our data used to train models? No. Matterfact does not train or fine-tune models on customer data, and does not permit subprocessors, including third-party model providers, to do so either. Your documents are indexed inside your single-tenant boundary.
Where does the deployment run? In an isolated environment dedicated to your fund, on AWS or Google Cloud. For firms with stricter requirements, Matterfact can deploy inside your own VPC or on-premise.
Can we restrict which models Matterfact calls? Yes. Outbound access is default-deny. Your team approves the specific model endpoints the system may reach, and every outbound call is logged. You can also bring your own API keys.
How are MCP connectors kept safe? Connectors run inside your tenant from a reviewed allowlist, with scoped credentials for each tool. Nothing is added without approval, and connector activity is logged.
What does your security review process look like? We share our SOC 2 Type II report, support DDQs and vendor reviews, and walk your security team through SSO and SAML, RBAC, TLS 1.3, and the audit logs.
Can compliance see what analysts ran? Yes. Audit logs are exportable and include outbound calls, so compliance and security teams can review all activity from the Matterfact environment.
What happens to our data if we leave? Content is made available for export on request, then deleted from active systems within 30 days, with residual backup copies aged out on the normal backup cycle. Full detail is in the Terms of Service.
Related pages
- Home: https://www.matterfact.com/
- Platform overview: https://www.matterfact.com/platform.md
- Terms of Service: https://www.matterfact.com/terms
- Privacy Policy: https://www.matterfact.com/privacy
- Site index for LLMs: https://www.matterfact.com/llms.txt
Getting started
Send us your DDQ or your security questionnaire before the deeper review. We will complete it, share the SOC 2 Type II report under NDA, and walk your security team through the deployment.
Book a demo: https://www.matterfact.com/?utm_source=llm&utm_medium=markdown&utm_campaign=security&utm_content=demo