Controlled-Pilot Security Overview
Security Boundary
Singular is offered as a controlled pilot with a qualified workload, route, provider, S-Core release, and named owners. This page describes controls present in the product and pilot process. It is not a certification, audit report, or substitute for a signed security or data agreement.
Data And Credential Protection
Customer provider credentials are encrypted before database storage and are write-only after submission. Singular API key secrets are stored as hashes and the plaintext is shown only when the key is created or rotated. Secrets must not appear in source control, release evidence, logs, screenshots, or support records.
Public pilot traffic is enabled only after the deployment has passed its HTTPS/TLS, readiness, migration, and route checks. Environment-specific credentials and database roles separate staging from production.
Tenant Access
Portal and control-plane access is derived from authenticated identity and scoped to a customer workspace. Roles limit administrative actions. The public API resolves the workspace from the Singular API key rather than trusting a customer identifier in the request body.
Operational records contain safe identifiers and aggregate outcomes. Access to a pilot is reviewed with its named customer and Mattom owners before activation.
Raw Content Default
Raw prompts, marked context, and raw provider responses are processed in memory and are not persisted by Singular by default. The provider configured by the customer still receives the request needed to produce its response, and the provider's own processing and retention terms apply.
Incident Response
The pilot has an owned incident process covering triage, containment, rollback, privacy-safe evidence, customer updates, and follow-up. Active pilots use their private operating channel and support@mattom.dev. Reports must include safe identifiers and timestamps, never raw traffic or secrets.
Suspected credential exposure, cross-tenant access, raw-content disclosure, or other security events should be reported immediately to security@mattom.io. Notification timing and any customer-specific obligation come from the executed pilot agreement; Singular does not publish an unsupported universal breach deadline.
DPA And NDA Path
Start a DPA, NDA, or security review through sales@mattom.io. Mattom coordinates the requested documents and questionnaire with legal@mattom.io. When the review determines that a document is required, it must be executed and its approval recorded before pilot traffic is enabled.
Contact
- Security incidents and vulnerabilities: security@mattom.io
- Active pilot operations: support@mattom.dev
- DPA, NDA, and security review intake: sales@mattom.io
- Legal coordination: legal@mattom.io