Skip to content

Security

Public security posture,without inflated claims.

What we can share publicly today about controls, review processes, and the current state of platform security.

Current posture

Controls you can check yourself

Everything below is visible in your own admin console rather than asserted here — the difference that matters when you are the one signing off.

Trust note

This page lists controls and open questions. It is not a certification.

The controls in this section ship in the product and you can verify each one in your own community. The section after it is what we answer in writing during evaluation rather than publish.

If your process needs formal evidence, do not treat marketing copy as proof — ask us and hold us to the contract.

Sign-in and sessions

Two-factor authentication, required email verification and Turnstile bot protection are community-level settings. Members and admins can list their active sessions, revoke one or all of them, and read their own sign-in history.

Enterprise identity

SAML 2.0 and OIDC with just-in-time provisioning and default role mapping, plus a dedicated sign-in audit log for the identity provider. Available from the Business plan.

Roles and audit trail

Admin access is role-based, account activity is captured in an audit log you can list and export, and moderation actions are recorded in a separate audit log of their own.

Data lifecycle, in your hands

Export your data at any time. Account deletion runs on a cooldown you can cancel within. A retention policy can notify, anonymize or delete inactive accounts after a number of months you set, with its own grace period, and messages carry their own retention window.

During evaluation

Answered in writing, then committed in the contract

These are real questions with real answers — they just should not be settled by a marketing page. Bring them to us and we put the answer where it is enforceable.

DPA and data handling

Processing terms, retention specifics and deletion guarantees, in the agreement rather than paraphrased here.

Data residency

Tell us the regional or sovereignty requirement you are working to and we confirm what we can commit to before you sign.

Uptime and response SLA

Availability and response-time commitments are agreed as part of an enterprise contract.

Architecture and subprocessors

Hosting, encryption, backups and the subprocessor list are answered for your questionnaire directly, because they change and a static page would go stale.

What is not publicly published yet

The two things buyers most often ask for that we do not have yet. We would rather you hear it here than after a procurement cycle.

SOC 2 report

Not published

We are not claiming a public SOC 2 Type II report or audit letter is available from this page today.

Penetration test summary

Not published

No public penetration test summary, letter of attestation, or continuous monitoring statement is posted here yet.

Reporting a security issue

For security-related reports and questions, email hello@mateflow.com or use the contact form below.

How to reach us

Email hello@mateflow.com or use the contact form.

Include reproduction steps, affected scope, and expected impact so we can route the issue quickly. For vulnerability reports, email hello@mateflow.com directly.

If you need a security conversation during procurement, use the same channel and mention that the request is for a security review.

Need a security review for your evaluation?

We can walk through the current product posture and clarify what is available today versus what is still being formalized.

Start free trial