Security Policy & Vulnerability Reporting
This page describes the practices we operate today. It is a description of our approach, not a certification, guarantee or warranty of security, and we make no claim of holding any third-party audit or certification unless we state so explicitly with the certificate.
How we protect the platform
- All traffic is served over TLS; stored data is encrypted at rest by our managed database and storage providers.
- Every record is scoped to the owning account through row-level authorisation, enforced in the database rather than only in the interface.
- Regulatory-tracker uploads, source configuration and the fetch audit log are restricted to Maatvia administrators and enforced server-side, so they cannot be reached by other users through direct API calls.
- Access tokens for connected Microsoft OneDrive or SharePoint accounts are stored using authenticated encryption and are never exposed to the browser.
- Card data is handled entirely by our payment processor; we never see or store full card numbers.
- Staff access follows least privilege, uses unique credentials with multi-factor authentication, and is reviewed and revoked promptly on role change.
- Privileged actions — including every tracker fetch run, with timestamp, workbook and result — are recorded in an audit log.
- Changes are peer-reviewed before deployment, dependencies are monitored for known vulnerabilities, and backups are taken continuously with restore testing.
Your part
- Use unique, strong passwords and enable available account protections.
- Grant seats only to people who need them and remove departing users promptly.
- Limit what you connect: point the integration at the specific folder needed, not an entire drive.
- Treat exported CSV and PDF reports as confidential once they leave the console.
Reporting a vulnerability
Email security@maatvia.com with a description, affected URL or endpoint, reproduction steps and any proof-of-concept. We acknowledge reports within 3 business days and aim to give a remediation plan within 10 business days.
Please act in good faith: use only your own test accounts, stop at the first proof of a finding, do not access, modify or exfiltrate other customers' data, avoid denial-of-service, spam, social engineering and physical attacks, and give us reasonable time to fix the issue before disclosing it publicly.
We will not pursue legal action against researchers who follow these guidelines. We do not currently operate a paid bug-bounty programme, but we credit reporters who wish to be named.
Incident response
If an incident affects customer data, we contain it, investigate, and notify affected account owners without undue delay and in any event within 72 hours of becoming aware, together with the facts known at that point and the steps we are taking.