GDPR
Matsivo is built and operated for use under the GDPR: lawful processing on your instructions, EU hosting, and support for data subject requests received through your organisation.
Security, privacy and reliability are built into every part of Matsivo.
This page is maintained by the Matsivo team to answer common security and privacy questions about the Matsivo platform. It describes controls that are in place today and clearly labels initiatives that are planned. It is not an independent audit or certification.
ScrollSix control areas describe how Matsivo protects customer data. Each one opens a detailed page.
Security is designed into the application layer: hardened HTTP responses, validated inputs and server-enforced business rules.
Read moreManaged identity, strong password requirements, throttling of repeated attempts and optional multi-factor authentication.
Read moreRole-based access control, per-establishment scoping and database-level row security applied to every request.
Read moreTLS in transit, encryption at rest on managed infrastructure, modern password hashing and centrally managed secrets.
Read moreSecurity audit events, application error capture and platform telemetry that make unusual activity visible.
Read moreManaged backups, recoverable infrastructure and a documented approach to incidents and planned maintenance.
Read moreMatsivo is a multi-tenant platform where isolation and permission checks are enforced in the database, not only in the interface.
Multi-tenant architecture
One hardened platform, strictly partitioned per organisation.
Tenant isolation
Every record is bound to an organisation and filtered by membership.
Role Based Access Control
Granular permissions resolved per organisation and establishment.
Row Level Security
Access rules live in the database and apply to every query.
Audit logging
Append-only security events that users cannot alter or remove.
Secure authentication
Managed identity, neutral errors and server-side throttling.
Multi-factor authentication
TOTP support with organisation-level enforcement.
Least privilege
Minimal grants for people, services and database roles.
Security headers
CSP, frame denial, cross-origin isolation on every response.
Secure APIs
Validated inputs, size limits and server-side authorisation.
Browser
TLS + hardened response headers
Application
Authenticated session, input validation
Domain action
Permission and MFA checks, audit entry
Database
Row Level Security, tenant scoping
Implementation details, provider names and configuration values are deliberately not published here.
Matsivo processes workforce data on behalf of your organisation. You stay in control of it.
Matsivo is built and operated for use under the GDPR: lawful processing on your instructions, EU hosting, and support for data subject requests received through your organisation.
Your organisation remains the controller of the data it records. Matsivo does not sell customer data and does not use it for advertising or profiling.
Planning, attendance, people and procurement data can be exported in structured, machine-readable formats at any time.
Records can be deleted in the application, and an administrator can request full deletion of a workspace. Audit records follow a defined retention horizon.
The product collects the data required to plan and pay for work. It does not track private location, personal messaging or off-duty activity.
Fields are limited to operational needs, and access is scoped to the establishments a user is responsible for.
Data processing terms and a subprocessor list are available on request at contact@matsivo.com.
Matsivo runs on managed European cloud infrastructure, deployed from version-controlled code.
Data is encrypted in transit and at rest, and credentials never leave the systems designed to hold them.
We welcome reports from security researchers and customers.
If you believe you have found a vulnerability in Matsivo, email security@matsivo.com with a description of the issue, the affected URL or endpoint, and the steps required to reproduce it. Please include enough detail for our team to validate the finding.
Machine-readable policy
Our contact details and disclosure policy are published as an RFC 9116 file:
/.well-known/security.txtOur current objective is to operate to enterprise expectations and to document our controls honestly.
EU hosting, data ownership, export and deletion support.
MFA, RBAC, row level security, audit logging and hardened headers.
Authorization enforced in the database; secure defaults for every new tenant.
Formal certification work is on the roadmap, not yet completed.
Planned. Matsivo is not SOC 2 certified today.
Planned. Matsivo is not ISO 27001 certified today.
Items marked Planned are future initiatives. Matsivo does not currently hold SOC 2, ISO 27001, ISO 27701 or CSA STAR certification, and makes no certification claim.
We monitor the platform continuously and communicate clearly when something changes.
Straight answers to the questions procurement and security teams ask most often.
Matsivo runs on managed European cloud infrastructure. Customer data — including your database, uploaded files and backups — is hosted in the European Union. If you need the specific hosting region for a procurement review, contact security@matsivo.com.
You do. Your organisation remains the owner and controller of the operational data it records in Matsivo. Matsivo processes that data to deliver the service and does not sell it or use it for advertising.
Yes. Planning, attendance, people and procurement data can be exported from the application in structured formats (CSV/Excel) and as PDF documents. For a complete extract of an organisation's data, an administrator can request one at contact@matsivo.com.
Yes. Records can be deleted in the application by users with the appropriate permission, and an organisation administrator can request full deletion of the workspace. Security audit records are kept for a defined retention period before automatic purge, because they are required for accountability.
Email security@matsivo.com with enough detail to reproduce the issue. Our published policy is available at /.well-known/security.txt. We acknowledge reports and keep researchers informed; we do not currently operate a paid bug-bounty programme.
Yes. Users can enrol a TOTP authenticator application, and organisations can require multi-factor authentication for their members. The requirement is checked on the server for sensitive operations.
Passwords are handled by a managed authentication service and stored only as salted one-way hashes. A minimum length of 12 characters is enforced, repeated failed attempts are throttled, and Matsivo staff cannot read your password.
The production database is backed up by the managed database platform, and the application itself is reproducible from version-controlled code. Restores are performed by the Matsivo engineering team; customers do not have direct access to backup files.
Talk to the people who build and operate Matsivo.