xMatix
Sign in Request demo
xMatix
PRODUCTS
SalesField SalesCRMRewardsClaimsInventoryProcurementWarehouse ManagementField ServiceServiceSupportTelephony & MessagingFinance & AccountingPayrollExpense ManagementCommercePortalsAnalytics & ReportingData StudioMobile AppSee all products →
PLATFORM
Platform overviewApp BuilderAutomationIntegrationsSecurity & GovernanceChange ManagementDevelopers
SENSE AI
Sense AI overviewSense AssistSense ControlSense VisionAI StudioTrust & governanceIn Claude & ChatGPTUse cases
SOLUTIONS
FMCG & DistributionManufacturing & Dealer NetworksAutomotive & DealershipsPharma & HealthcareConsumer DurablesAgri-InputsBuilding MaterialsService NetworksWarehousing & 3PLFinancial AccountingERP SoftwareIndia GST ComplianceUAE VAT & e-InvoicingSaudi ZATCA & VATAll solutions →
RESOURCES
Knowledge CenterDeveloper & CLIBlogGuidesWhat is xMatix?Company facts
COMPANY
AboutCareersPartnersEventsContactAuthorsLegal
Sign in Request demo
PLATFORM · TRUST CENTER

How xMatix is run.

No badges, no vague assurances — the actual mechanics: how tenants are isolated, how access is decided, how change reaches production, and how the AI is governed. All of it demonstrable live.

THE PRACTICES

Security you can inspect, not just believe.

TENANT ISOLATION
Your data lives in your tenant.
Isolation is enforced at the data layer — multi-tenant efficiency without multi-tenant exposure.
ACCESS CONTROL
Two layers, down to the field.
Profiles govern actions; record-access policies govern visibility — with field-level security and an "explain why" diagnostic for any verdict.
AUDIT & RETENTION
Every change, attributed.
A full audit trail on data and configuration, plus a recycle bin with retention — deleted is not destroyed.
CHANGE CONTROL
Production changes with receipts.
Sandboxes with masked data, reviewed change sets, before-image undo, and drift detection that blocks blind applies.
AI GOVERNANCE
Sense runs as the user.
The AI inherits both access layers on every question, drafts changes preview-first behind approval gates, and spends against explicit credit budgets.
ENTITLEMENTS
Licensing you can read.
Product → feature → capability licensing with per-tenant usage metering — no surprise switches, no hidden meters.

Running a security review?

Every mechanism on this page is demonstrable live — bring your architects and your checklist to the demo.

Book a review demo
TENANT OPERATIONS

Operate it without a support ticket.

The evidence lives in the tenant's own setup console — administrators diagnose jobs, imports, messages and access questions themselves, from the same governed experience as everything else.

AUDIT
Audit browser
Every data and configuration change, searchable in setup — who, what, when, from which surface.
JOBS
Scheduled jobs & run history
Every recurring job with its run ledger — when it ran, what it did, and why it failed when it failed.
IMPORTS
Import & export history
Bulk loads with per-run results, so a bad file is diagnosed from the history, not re-run blind.
MESSAGING
Message logs
Outbound email and notification delivery, inspectable per message — sent, delivered, or why not.
TRACING
Trace diagnostics
Request-level traces for the tenant, so "it was slow at 3pm" becomes an answerable question.
LICENSING
License usage
Seats and capability consumption against entitlements — visible before renewal, not discovered at it.
SECURITY REVIEW

The questionnaire, answered in the open.

Where is customer data hosted?

In cloud data-centre regions in India. The production platform — application services, relational databases, the document store, file storage, caches and telemetry — runs in an Indian region, and backup storage is replicated to a second Indian region. Data residency for AI requests is covered on Sense trust & governance.

How is data encrypted?

TLS 1.2 or higher is the enforced minimum on every connection — at the network edge and on every internal hop to the databases, document store, file storage and cache. At rest, every store is encrypted: relational databases under transparent data encryption, and the document store, file storage and backups under platform-managed encryption.

How are secrets and service credentials handled?

Secrets live in a managed vault, never in code or configuration files. Platform services authenticate to data stores and to each other with platform-managed workload identities rather than shared passwords — there is no standing credential to leak or rotate by hand.

What do backups and recovery look like?

Operational databases take automated, encrypted backups with point-in-time restore over a rolling window; configuration stores are backed up on a fixed cycle to geo-replicated storage within India. Formal recovery objectives (RPO/RTO) are documented in the business-continuity plan, available under NDA.

How long are audit logs retained?

The application audit trail is tenant data: it records every data and configuration change with the acting identity, lives inside the tenant, and is retained for the life of the tenancy. Operational telemetry — service logs and metrics — is retained for 30 days.

How is data deleted?

In-app deletion passes through a recycle bin with a retention window, so deleted is not destroyed until the window lapses. On termination, tenant data is deleted in line with the Data Processing Addendum, and certification of deletion is available on request.

Are you SOC 2 or ISO 27001 certified?

Both certifications are in progress. Until the reports are issued, the underlying documentation set — security policies, architecture descriptions and test summaries — is available under NDA; the table below lists each artifact and its status.

Can we diagnose failures ourselves, or does every question become a ticket?

Yourselves, from the tenant's setup console: scheduled jobs carry their run history, imports keep per-run results, message logs show delivery per message, and request-level tracing is available for the tenant. The same console covers audit history and license usage — the operational evidence an evaluation asks for is the tenant administrator's to inspect, not ours to export.

DOCUMENTS & CERTIFICATIONS

What exists, and how to get it.

Statuses are kept current. To request a document under NDA, write to sales@xmatix.com or ask your account contact.

DocumentStatus
SOC 2 Type II reportIn progress
ISO 27001 certificateIn progress
Penetration-test executive summaryAvailable under NDA
Vulnerability-management policyAvailable under NDA
Incident-response policyAvailable under NDA
Disaster-recovery & business-continuity plan, incl. RPO/RTOAvailable under NDA
Data Processing AddendumPublished
Subprocessors listPublished
Privacy PolicyPublished
Responsible AI statementPublished
GO DEEPER
Security & GovernanceAI Trust & governanceChange Management
Platform overview →