Security & Trust

Your construction data is critical business data. Here's exactly how we protect it.

✓ HTTPS/TLS Encrypted ✓ Daily Backups ✓ Multi-tenant Isolation ✓ JWT Authentication ✓ Audit Logging

Data Protection

We apply multiple layers of protection to keep your project and financial data secure.

🔒

Encryption in Transit

All data between your browser and our servers is encrypted using TLS 1.2/1.3. We enforce HTTPS on all endpoints — no unencrypted connections are accepted.

🗄️

Encryption at Rest

Your database and file storage are encrypted at rest. Sensitive fields including passwords are hashed using bcrypt — we never store plain-text passwords.

🏢

Multi-Tenant Isolation

Every company's data is completely isolated. Your projects, workers, invoices, and BOQ data are never accessible to other tenants — enforced at the database query level.

Access Control

Strong authentication and authorization across every feature.

🔑 JWT Authentication

  • Signed JSON Web Tokens for every session
  • Tokens expire after 7 days — automatic re-authentication
  • Tokens are validated on every API request
  • Password reset tokens expire in 1 hour

👥 Role-Based Access Control

  • Admin, Staff, and User roles with distinct permissions
  • SuperAdmin role for platform management only
  • Feature gating by subscription plan
  • All access decisions enforced server-side

📋 Audit Logging

  • Complete trail of all user actions
  • Timestamps, user ID, and IP address logged
  • Available to Business plan subscribers
  • Logs retained for 12 months

💳 Payment Security

  • Payments processed by Paddle — PCI-DSS compliant
  • We never store card numbers or payment details
  • Paddle acts as Merchant of Record
  • Webhook signatures verified via HMAC-SHA256

Infrastructure & Reliability

Built on reliable infrastructure with proactive monitoring.

99.5%
Target uptime SLA
Daily
Automated backups
EU
Data center location
nginx
Reverse proxy + SSL
💾

Daily Backups

Automated daily database backups with point-in-time recovery capability. Backups are stored separately from primary data and retained for 30 days.

🌐

DDoS Protection

Network-level DDoS mitigation via our infrastructure provider. Rate limiting applied on all API endpoints to prevent abuse.

📊

Monitoring

24/7 uptime monitoring with automated alerts. Application errors are logged and reviewed. PM2 process manager ensures automatic restart on failure.

Responsible Disclosure

Found a security vulnerability? We take all reports seriously.

🔍 How to Report

  • Email us at info@matrixnet.com.np
  • Subject line: "Security Vulnerability Report"
  • Include steps to reproduce the issue
  • We will acknowledge within 48 hours
  • We will keep you updated on our progress

✅ Our Commitment

  • We will not take legal action against good-faith researchers
  • We will fix confirmed vulnerabilities promptly
  • We will credit researchers in our release notes (if desired)
  • We treat all reports with confidentiality

Security questions or concerns?

Our team responds to all security inquiries within 48 hours.

Contact Security Team →