What we do with your data. And what we never do
Plain answers, no certification theater. Exactly how your data is connected, encrypted, kept, and deleted.

Five commitments. No fine print
Every one of them is a rule the code enforces, not a policy we intend to follow. The screen beside this is what a funder is handed.

Everything a funder receives with your file. Not your bank login, not your selfie, and not your ID photo unless you release it to them by name.
Bank connections
Live
You share your finances by connecting a business bank account. We never ask for or see your bank login. Uploading recent statements remains available if you do not connect.
You can connect a business bank account directly through Plaid. Plaid is the regulated infrastructure provider trusted by Venmo, Robinhood, and every major US neo-bank. You authenticate directly with Plaid, we still never see your login, and Plaid hands us read-only transaction data. Plaid cannot initiate any transfer on your behalf.
You can revoke Plaid access in your bank's dashboard or Plaid's consumer portal and our access will stop immediately.
Business credit bureaus
Connection pending
No bureau contract is in place. Experian, Equifax, and Dun & Bradstreet clients in this app are mocks. Production pulls fail closed: a live inquiry is refused rather than served from sample data.
Encryption
- TLS 1.3 in transit on every connection to our servers.
- Sensitive fields are encrypted with XSalsa20-Poly1305 (libsodium secretbox).
- At rest, our managed Postgres volume is encrypted with AES-256.
- Secrets are stored as Vercel environment variables, never checked into git.
- Our production database runs on managed Postgres with app-layer tenant isolation, authenticated server access, and audited permission checks before sensitive records are read.
Data retention
When you request account deletion, from your account settings or by email to info@newmatrix.capital, we erase your financial and personal records in a single operation and disconnect any linked bank account. The deletion is immediate and cannot be reversed, so we verify the request before we run it. What remains is limited to the anonymized analytics fields described below, and any record a specific law requires us to keep. Backup and derived copies roll off within 30 days of account closure.
For underwriting analytics we keep only de-identified fields such as state, industry, monthly revenue bucket, and FICO bucket. We are automating that de-identification; until it is in place, we strip names, EINs, and account-level data by hand when you request it at info@newmatrix.capital.
Incident response
In the event of a confirmed data breach affecting borrower or lender accounts, affected users are notified within 72 hours via the email on file. A public incident report is published in our incident register on the date of remediation, covering scope, root cause, mitigation, and remaining risk.
Where we actually stand
We have not undergone a SOC 2 audit. As the platform scales we will commission an independent audit. Until then, this page is our public commitment to the practices above. We list this rather than hide it because the alternative is implying certifications we do not have, which is the exact pattern we built this platform to be the opposite of.
Connection pending
Generic earner payouts are off. ISO Connect transfers are not live. Earnings can accrue on the ledger; this app does not send those funds until the payout rail is switched on.
If you find a vulnerability, please email info@newmatrix.capital. We respond within one business day.
The same honesty applies to the money
We publish our commercial model in full and explain exactly what separates us from the broker industry.