Skip to main content
Security transparency

Incident reports

Material incidents that affect customer data or platform availability are listed here after investigation and remediation, with scope, response, and remaining risk. Today there are none.

The ledger

No public incident reports

Nothing has met the publication bar below. When something does, it appears here and is not quietly removed later.

Nothing published to date

To report a potential vulnerability, email info@newmatrix.capital. We answer researchers, and we do not pursue anyone who reports in good faith and gives us time to fix it. The same contact is published at /.well-known/security.txt.

The publication bar

What we commit to publish, and when

Written down before there is anything to report, so the rule cannot be decided after the fact. The screen beside this is the scope any notice would have to describe.

A merchant’s data and sharing record: which funders hold the file, what each can see, and the authorizations on record
SampleReal product, seeded demo data

“Scope” is not an abstraction here. Every account can already see exactly which data exists and who holds it.

What gets published

Any incident that affects customer data or platform availability, once the investigation is closed and the fix is in place. Not near misses, not blocked attempts, not routine vulnerability patching - those are handled and logged without a public notice.

When

Regulatory notification runs on the deadline the affected state sets, and it happens whether or not a notice appears here. The public notice on this page follows remediation, so it can say what was actually done rather than what was planned.

What the notice contains

Scope - which data, how many accounts. Response - what we did and when. Remaining risk - what a customer should still do. Written plainly, not in the language a breach notice is usually written in.