Skip to main content

Your data, our AI, and who decides

Every AI provider we use is bound by a zero data retention agreement, and we do not train or fine-tune any model on your data. The AI never changes anything on its own: every proposed change is approved by a person before it enters your records, and can be undone.

For taking a demo with our team.

Matrix One

The challenge

The questions that stop an AI pilot in a regulated company

These come up in every vendor assessment, and a vague answer to any one of them ends the conversation. Where does our data go? Regulated teams need to know what leaves the system, who processes it and what is kept afterwards. Are you training on it? A model trained on your quality data is a confidentiality problem, not a feature. Can it change our records? An assistant with write access to a controlled document is an audit finding waiting to happen. How would we validate it? Software validation expects a defined, repeatable step, and generation on its own is not one.

    Our solution

    Commitments, not intentions

    These are the terms every AI feature on the platform already operates under today. Zero data retention with every provider. Every AI provider we use (Anthropic, Google Gemini, AWS Bedrock) is bound by a zero data retention agreement. Your data is processed only to answer your request, is never stored by the provider, and is never used to train a model. Matrix One stores your conversation history so you can come back to it. No training on your data. We do not train or fine-tune any model on your data, and we do not share, sell or disclose customer data. Nothing changes on its own. Each proposed change is shown as a redline, applied only when a person approves it, done with that person's permissions, and can be undone. The AI never deletes records. A step you can validate. The validated step in your procedure is the human review, not the generation. Human review before anything is written. All AI generated content appears in a review interface and enters your documentation only on your explicit validation and confirmation. Your data stays yours. It remains the exclusive property of your organisation at all times, input and output alike.

      Where these commitments apply

      The same terms cover every AI feature, not just the ones a security questionnaire happens to ask about.

      Matrix Mind

      Grounded in your live project data. It proposes changes as redlines and applies them only when a person approves.

      Learn more

      Compliance Checker

      Every assessment goes to a review interface first, and results export as CSV for offline validation.

      Learn more

      AI Features and Data Handling

      The detail behind the commitments: what each AI feature touches, and how zero data retention applies to it.

      Learn more

      AI-supported Risk Management

      Risk work assisted by AI, with risk acceptability decisions left where they belong.

      Learn more

      Technical Documentation

      Generated content presented for review and imported only once you confirm it.

      Learn more

      Matrix Req

      The platform these features live inside, with its own access controls and audit trail.

      Learn more

      FAQ

      01Is our data used to train AI models?

      No. We do not train or fine-tune any model on your data. Our AI features rely on pre trained models from Anthropic, Google Gemini and AWS Bedrock, which process input solely to answer your request under a zero data retention agreement.

      Model providers keep nothing. Matrix One stores your conversation history so you can come back to it.

      02Where is the AI processing done?

      With the AI providers we use. Every AI provider we use (Anthropic, Google Gemini, AWS Bedrock) is bound by a zero data retention agreement. Your data is processed only to answer your request, is never stored by the provider, and is never used to train a model.

      03Can the AI delete or overwrite our records?

      No. The AI never changes anything on its own. Each proposed change is shown as a redline, applied only when a person approves it, done with that person's permissions, and can be undone. It never deletes records.

      04How would we validate an AI assisted step?

      Validate the review, not the generation. The validated step in your procedure is the human review: a named person approves each change as a redline, the change is made with their permissions, and the reason lands in the audit trail.

      05Who owns the output the AI generates?

      You do. Your data remains the exclusive property of your organisation at all times, whether it is input data or output generated through our AI features. Matrix One and its suppliers acquire no rights, title or interest in it.

      06Can we export AI results for offline review?

      Yes. Compliance Checker results can be exported as CSV, so your team can review, discuss and validate assessments outside the platform before incorporating anything into your technical documentation.

      07Does zero data retention cover our own AI assistant connected through MCP?

      No. When you connect your own assistant, such as Claude or Cursor, through the Matrix Req MCP connection, your data goes to the AI provider you chose, under your own agreement with that provider. Our zero data retention agreements cover the AI features built into Matrix Req.