Security and governance, stated plainly.
How we approach infrastructure and operational data, and what we ask you not to send us.
Last updated 12 October 2026
MTRX may involve infrastructure information, operational data, asset details and connections to institutional systems. We take a serious, discovery-led approach, and we describe security practices only to the level that has been verified.
What this website does
- Uses HTTPS.
- Does not ask you to upload confidential files or enter passwords, API keys or secrets into public forms.
- Does not publish sensitive diagrams, private endpoints or detailed customer architecture.
- Collects analytics on button clicks and successful submissions without recording form contents or personal identifiers.
What we define with you in every project
- Data ownership and permitted use.
- User roles and access control.
- Hosting, data residency and institutional requirements.
- Integration credentials, secrets handling and rotation.
- Data refresh, quality, lineage and failure handling.
- Model and asset data update responsibilities.
- Human oversight and escalation for operational alerts.
- Backup, incident response, continuity and exit or data export arrangements.
How technical information is exchanged
After an enquiry is qualified, we arrange a controlled process for sharing technical documentation. Please do not send credentials, network diagrams or confidential files before then.
Certifications and assurances
We do not claim security certifications, compliance badges or audit statements on this site. If you need specific assurances for procurement, ask in your enquiry and we will confirm what can be provided for your project.
Report a security or privacy concern
Use the contact form and choose “Security or privacy question”. Please describe the issue in general terms and do not include secrets.
