Last Updated: January 30, 2026
MatterGuard is designed with security and compliance at its core. This document provides an overview of our security architecture, data protection practices, and PDPA compliance measures for law firms evaluating our platform.
MatterGuard is designed to help law firms comply with the Personal Data Protection Act 2012 (PDPA) of Singapore. Key compliance features include:
Consent Management
Track and document consent for data processing
Purpose Limitation
Data used only for stated KYC/AML purposes
Access & Correction
Tools to respond to data subject requests
Data Protection
Technical safeguards exceeding PDPA requirements
Retention Limits
Configurable retention with secure deletion
Transfer Safeguards
Compliant international data transfers
| Layer | Controls |
|---|---|
| Network | Web Application Firewall (WAF), DDoS protection, VPC isolation, intrusion detection/prevention |
| Application | Input validation, CSRF protection, XSS prevention, secure session management, rate limiting |
| Data | Encryption at rest (AES-256), encryption in transit (TLS 1.3), key management via HSM |
| Identity | OAuth 2.0, MFA, role-based access control, session timeout, password policies |
| Operational | 24/7 monitoring, incident response procedures, regular penetration testing, vulnerability scanning |
Our incident response process ensures rapid detection, containment, and resolution of security incidents:
Type II Certified
Data Center Certified
Singapore Compliant
For security inquiries, vulnerability reports, or to request our SOC 2 report:
MatterGuard Pte. Ltd.
Security Team: [email protected]
For urgent security matters, please include "URGENT" in the subject line.
© 2026 MatterGuard Pte. Ltd.. All rights reserved.
Document Version: 1.0 | Last Updated: January 30, 2026