Skip to main content

Your data, our AI, and who decides

Matrix One processes AI requests on AWS Bedrock under strict zero data retention. We do not train models on customer data or on public data. The AI cannot alter or delete anything in your system, and every output is reviewed by a person before it enters your records.

Matrix One
The challenge
Our solution

The questions that stop an AI pilot in a regulated company

Four commitments, not four intentions

These come up in every vendor assessment, and a vague answer to any one of them ends the conversation.

Where does our data go? Regulated teams need to know what leaves the system, who processes it and what is kept afterwards.

Are you training on it? A model trained on your quality data is a confidentiality problem, not a feature.

Can it change our records? An assistant with write access to a controlled document is an audit finding waiting to happen.

How would we validate it? Software validation expects a defined, repeatable step, and generation on its own is not one.

These are the terms every AI feature on the platform already operates under today.

Zero data retention. Processing runs on AWS Bedrock under strict zero data retention. Your input is used to generate the output you asked for and is not kept afterwards.

No training on your data. We do not train any model on customer data or on public data, and we do not share, sell or disclose customer data.

No write access. The AI has no capability to alter, delete or manipulate existing data in your system.

Human review before anything is written. All AI generated content appears in a review interface and enters your documentation only on your explicit validation and confirmation.

Your data stays yours. It remains the exclusive property of your organisation at all times, input and output alike.

The challenge

The questions that stop an AI pilot in a regulated company

These come up in every vendor assessment, and a vague answer to any one of them ends the conversation.

Where does our data go? Regulated teams need to know what leaves the system, who processes it and what is kept afterwards.

Are you training on it? A model trained on your quality data is a confidentiality problem, not a feature.

Can it change our records? An assistant with write access to a controlled document is an audit finding waiting to happen.

How would we validate it? Software validation expects a defined, repeatable step, and generation on its own is not one.

Our solution

Four commitments, not four intentions

These are the terms every AI feature on the platform already operates under today.

Zero data retention. Processing runs on AWS Bedrock under strict zero data retention. Your input is used to generate the output you asked for and is not kept afterwards.

No training on your data. We do not train any model on customer data or on public data, and we do not share, sell or disclose customer data.

No write access. The AI has no capability to alter, delete or manipulate existing data in your system.

Human review before anything is written. All AI generated content appears in a review interface and enters your documentation only on your explicit validation and confirmation.

Your data stays yours. It remains the exclusive property of your organisation at all times, input and output alike.

Where these commitments apply

The same terms cover every AI feature, not just the ones a security questionnaire happens to ask about.

Matrix MindGrounded in your live project data, with no capability to alter or delete what it reads.Learn more
Compliance CheckerEvery assessment goes to a review interface first, and results export as CSV for offline validation.Learn more
AI Features and Data HandlingThe detail behind the commitments: what the plugins touch, and the zero data retention policy in full.Learn more
AI-supported Risk ManagementRisk work assisted by AI, with risk acceptability decisions left where they belong.Learn more
Technical DocumentationGenerated content presented for review and imported only once you confirm it.Learn more
Matrix ReqThe platform these features live inside, with its own access controls and audit trail.Learn more

FAQ

Is our data used to train AI models?

No. We do not train any model on customer data or on public data. Our AI agents rely on pre trained models from trusted providers, which process input solely to generate the requested output under a zero data retention condition.

Third party providers process customer data temporarily and do not retain or reuse it.

Where is the AI processing done?

On AWS Bedrock, which adheres to strict zero data retention principles. Information you provide, such as device descriptions or regulatory documentation, is processed only to generate the output you asked for.

Can the AI delete or overwrite our records?

No. The AI does not have the capability to alter, delete or manipulate any existing data within your systems. All outputs are subject to human review and validation before any decision or change is implemented.

Who owns the output the AI generates?

You do. Your data remains the exclusive property of your organisation at all times, whether it is input data or output generated through our AI plugins. Matrix One and its suppliers acquire no rights, title or interest in it.

Can we export AI results for offline review?

Yes. Compliance Checker results can be exported as CSV, so your team can review, discuss and validate assessments outside the platform before incorporating anything into your technical documentation.