# MatterFirst buyer evidence pack

What protects a firm's information in MatterFirst, what each claim rests on, how sure we
are, and when it was last checked. The same page is at matterfirst.com/trust. Each piece
of evidence says what kind it is; ask us to walk your adviser through any of them.

Last checked: 23 September 2026. MatterFirst holds no security certification and
claims none.

## Independent assessment

What outside parties have checked. Nothing yet, and we say so first.

- **Not done yet.** MatterFirst holds no SOC 2 report, ISO 27001 certificate or other third-party security certification, and claims none. Evidence: Security page answer (page at matterfirst.com/security); Rule against certification claims (product code). Checked 23 September 2026.
- **Not done yet.** No independent penetration test has been carried out. Evidence: Limitations recorded for this build (engineering record). Checked 23 September 2026.
- **Not done yet.** No independent legal or compliance review of the product has been completed. The identity-check feature is a demonstration for that reason. Evidence: Identity-check design (engineering record). Checked 23 September 2026.

## Where information goes, and who processes it

Each service that receives a firm's information, where it runs, and the switch the firm uses to stop it. Firms see and change these switches in Settings › Security & data › Where data can go.

- **Set in the deployment configuration.** The application runs on Fly.io in its Sydney region. Evidence: Deployment file: primary region Sydney (deployment configuration); The database address is supplied when the application starts (deployment configuration). Checked 23 September 2026.
- **Set in the deployment configuration.** Documents are stored in Amazon Web Services S3 in Sydney. Evidence: Storage bucket and region in the deployment file (deployment configuration). Checked 23 September 2026.
- **Set in the deployment configuration.** The AI assistant, drafting and document analysis use Amazon Web Services Bedrock with Australian model routing. The firm's “AI assistant” switch stops it, including work already queued. Evidence: Region default (deployment configuration); The switch, in Settings › Security & data › Where data can go (page in MatterFirst, for a signed-in firm); Switch enforced on every AI call (automated test). Checked 23 September 2026.
- **Set in the deployment configuration.** Reading the text out of a document runs on Microsoft Azure AI Document Intelligence in Azure's Australia East region, not in Amazon Web Services. Evidence: Azure region default (deployment configuration). Checked 23 September 2026.
- **Partly in place.** Notifications and reminders use Resend. The firm's email-delivery control stops firm reminders and notifications; sign-in and invitation emails always send. Evidence: Data-exit inventory (engineering record); Switch enforced (automated test). Checked 23 September 2026.
- **Partly in place.** Crash reporting uses Sentry when configured, with request-content scrubbing. Evidence: Crash report scrubbing (automated test). Checked 23 September 2026.
- **Checked by automated tests.** An email filed to a matter is copied into MatterFirst; the original stays in the firm's Microsoft 365 or Google Workspace mailbox. Calendar events are copied between MatterFirst and the firm's calendar. Invoices go to the firm's own Xero, and card payments to the firm's own Stripe account. Every one of these connections passes the firm's switch for it before anything is sent. The integrations a firm can connect today are Google Workspace, InfoTrack, Microsoft 365, PEXA, Stripe and Xero. Evidence: Filed email is stored once in MatterFirst (automated test); A switched-off provider is not contacted (automated test); Every provider goes through its switch (automated test); Integration support boundaries (engineering record); What a firm can connect, and who looks after what, in Settings → Connected accounts (page in MatterFirst, for a signed-in firm). Checked 23 September 2026.
- **Checked by automated tests.** Every time information leaves, MatterFirst records where it went, why, for which matter and who asked, never the content, and the firm can read that record. Evidence: Sharing record (automated test); Recent sharing on the settings page (automated test); Recent sharing, in Settings › Security & data › Where data can go (page in MatterFirst, for a signed-in firm). Checked 23 September 2026.

## Keeping each firm's information separate

Every firm shares one application and one database, so separation is enforced in code and in the database itself.

- **Checked by automated tests.** Every read of firm information is filtered to the firm in one place, and a read that does not say which firm it is for is refused rather than answered. Evidence: The filter (product code); Isolation tested for every firm table (automated test); Undeclared reads refused (automated test). Checked 23 September 2026.
- **Checked by automated tests.** The database refuses a record in one firm that points at another firm's record. Evidence: Cross-firm references refused (automated test); Composite keys on every firm table (automated test). Checked 23 September 2026.
- **Checked by automated tests.** An API key belongs to one firm, acts as the person who created it, and reaches only what its scopes allow. Evidence: Scopes enforced (automated test); Sample integration against the real API (automated test); Keys and scopes, in the developer guide (page at matterfirst.com/docs/developers). Checked 23 September 2026.

## Who can do what, and the record of it

Access is by role, checked on the server for every change.

- **Checked by automated tests.** Every change a person can make on a page is checked against their role on the server, and anything not explicitly allowed is refused. Evidence: Every page action classified (automated test); Refusals (automated test). Checked 23 September 2026.
- **Partly in place.** Changes are recorded in an audit log a firm can export through the API (GET /api/v1/audit-log), with secrets removed. Some older changes do not yet write an audit entry. Evidence: Audit export (automated test); Known gap, recorded in the engineering notes (engineering record); The audit log in the API reference (page at matterfirst.com/docs). Checked 23 September 2026.
- **Checked by automated tests.** A firm's owner can export everything at any time, not only on request: every record as spreadsheets, every document, a guide, and a program that checks the copy without MatterFirst. Only an owner can make or download one, and each copy can be downloaded for 7 days. Evidence: Settings → Your data → Export everything (page in MatterFirst, for a signed-in firm); An export checks out from its own files (automated test); Only an owner exports (automated test). Checked 23 September 2026.
- **Checked by automated tests.** Revoking an API key, or deactivating the person who created it, stops it at once. Evidence: A revoked key is refused (automated test); A key whose creator is deactivated is refused (automated test). Checked 23 September 2026.

## Backups and a restore exercise

How a firm's information would be recovered, and whether that has been tried.

- **Not done yet.** A restore exercise is written down (below) but has not been run yet. Running it needs operator access to the production database host. Evidence: The procedure (engineering record). Checked 23 September 2026.

### Restore exercise procedure

1. Choose a recent backup of the production database and note its time.
2. Restore it to a new, separate database. Never restore over production.
3. Start a staging copy of MatterFirst against it with every outside connection off: no email, webhooks, AI or provider credentials, and every firm's data-sharing switches off.
4. Confirm every migration is applied, and run the firm-isolation checks against the copy.
5. Compare with production at the backup time: number of firms, matters and documents, and trust account totals. Open three matters and one document in the staging copy.
6. Record the backup time, when the restore started and finished (how long recovery takes), how much recent work would have been lost, who ran it, and anything that failed.
7. Destroy the restored copy, and add the result to this pack with its date.

## Support and incidents

How a firm gets help, and what MatterFirst does when something goes wrong.

- **Checked by automated tests.** Anyone at a firm can raise a support request from Help in the app and follow it there. Evidence: Raising and following a request (automated test); Help, in MatterFirst (page in MatterFirst, for a signed-in firm). Checked 23 September 2026.
- **Checked by automated tests.** In an incident, a firm (or MatterFirst for every firm) can stop information leaving through any destination at once, including work already queued; the sharing record then shows which matters were affected. Evidence: Queued work stops (automated test); The record says what was affected (automated test). Checked 23 September 2026.
- **Partly in place.** The incident steps are written below. They have not been rehearsed, and notification times are not yet set out in the customer agreement. Evidence: The steps (engineering record). Checked 23 September 2026.
- **Checked by automated tests.** Routine logs on the AI, integration and email paths do not quote client content. Evidence: Log content checked (automated test). Checked 23 September 2026.

### Incident steps

1. Notice: an error alert, an unusual pattern in the sharing record, or a report from a firm.
2. Contain: switch off the affected destination, revoke affected keys or connections, and pause the affected background work.
3. Assess: use the sharing record and the audit log to work out which firms, matters and kinds of information were involved, and whether it left MatterFirst.
4. Tell each affected firm what happened, what was involved and what they may need to do, so they can meet their own obligations to their clients.
5. Fix the cause, add a test that would have caught it, and record what was learned.

## Security checks run on every build

Automated checks in MatterFirst's own code, run by the full test suite. They are not an independent test.

- **Checked by automated tests.** Firm isolation, role checks on every page action, API scopes, refusal of private network addresses for webhooks and integrations, the outside-AI pause, the data-sharing switches and hostile instructions hidden in documents are each covered by automated tests. Evidence: Firm isolation (automated test); Page actions (automated test); API scopes (automated test); Private addresses refused (automated test); Outside-AI pause (automated test); Data-sharing switches (automated test); Hostile document content (automated test); Last recorded full run (engineering record). Checked 23 September 2026.
- **Checked by automated tests.** Build guards fail the build on an unscoped read, a swallowed error, or an unscoped query into a matter table. Evidence: Scope guard (automated test); Error guard (automated test); Wall guard (build check). Checked 23 September 2026.

## Limitations

What is not done, so nobody has to find out later.

- **Checked by automated tests.** Ethical walls are not offered: they are switched off for every firm. Connections to and from outside AI tools are paused. Evidence: Walls inert (automated test); Outside AI paused (automated test); What is switched off, in the developer guide (page at matterfirst.com/docs/developers). Checked 23 September 2026.
- **Partly in place.** Only meeting invitations through Microsoft 365 have been checked against a real provider account. Microsoft 365 mail and calendar sync, Google, Xero and Stripe are checked by automated tests only; the live checks for Microsoft 365 mail and Stripe test mode are written down and waiting to be run. Evidence: Integration verification (engineering record); Who looks after what, in Settings → Connected accounts (page in MatterFirst, for a signed-in firm). Checked 23 September 2026.

## The claims on our website

Each short claim the website shows under its headings, with what it rests on.

- **Set in the deployment configuration.** “Encrypted in transit” (shown on the website): every connection is forced to HTTPS. Evidence: HTTPS enforced, with HSTS (deployment configuration); HTTPS only (deployment configuration). Checked 23 September 2026.
- **Set in the deployment configuration.** Documents are stored in Sydney, and document AI processing runs in Australian regions. Evidence: Storage bucket in Sydney (deployment configuration); AI and document-reading regions (deployment configuration). Checked 23 September 2026.
- **A commercial term; check it in your agreement.** “No lock-in contracts” (shown on the website): plans are priced by the month. Evidence: Prices shown per month (page at matterfirst.com/pricing). Checked 23 September 2026.
- **A commercial term; check it in your agreement.** “Guided setup available” (shown on the website): setup is offered with a guided trial. Evidence: Guided trial (page at matterfirst.com/pricing). Checked 23 September 2026.
- **Checked by automated tests.** “Your data exportable on request” (shown on the website): a firm's owner can export everything at any time from Settings → Export everything (every record as spreadsheets and every document, with a program that checks the copy), and records are also available through the API. Evidence: Settings → Your data → Export everything (page in MatterFirst, for a signed-in firm); An export checks out from its own files (automated test); The API (API description at /api/v1/openapi). Checked 23 September 2026.
