Incident reports
Material incidents that affect customer data or platform availability are listed here after investigation and remediation, with scope, response, and remaining risk. Today there are none.
No public incident reports
Nothing has met the publication bar below. When something does, it appears here and is not quietly removed later.
Nothing published to date
To report a potential vulnerability, email info@newmatrix.capital. We answer researchers, and we do not pursue anyone who reports in good faith and gives us time to fix it. The same contact is published at /.well-known/security.txt.
What we commit to publish, and when
Written down before there is anything to report, so the rule cannot be decided after the fact. The screen beside this is the scope any notice would have to describe.

“Scope” is not an abstraction here. Every account can already see exactly which data exists and who holds it.
What gets published
Any incident that affects customer data or platform availability, once the investigation is closed and the fix is in place. Not near misses, not blocked attempts, not routine vulnerability patching - those are handled and logged without a public notice.
When
Regulatory notification runs on the deadline the affected state sets, and it happens whether or not a notice appears here. The public notice on this page follows remediation, so it can say what was actually done rather than what was planned.
What the notice contains
Scope - which data, how many accounts. Response - what we did and when. Remaining risk - what a customer should still do. Written plainly, not in the language a breach notice is usually written in.
How the data is protected in the first place
Encryption, access scope, what a funder can and cannot see of your file, and the sub-processors involved.