Your data in safe hands
Read our data privacy policies to understand how we process and manage your data:
Mattermaps is built on a fundamental principle: your data belongs to you. We provide the infrastructure for secure environmental data exchange, but the control over what is shared, when, and with whom always stays with your organization. Every aspect of our platform, from architecture to certifications, is designed to protect the confidentiality and integrity of your product data.
Data Sovereignty & Ownership
You decide what gets shared.
Product data on Mattermaps is stored separately and confidentially for each organization. Nothing is automatically visible to other participants on the network. Sharing only happens through explicit, controlled workflows that you initiate — you choose exactly what data to share, with whom, and when. Product Carbon Footprint (PCF) certificates and all associated data remain solely owned by your organization at all times. For full details, see our Privacy Policy and Terms & Conditions.
Security by Design
Mattermaps is operated by Makersite GmbH, a company with security at its core. Our infrastructure runs on AWS with defense-in-depth architecture: network segmentation isolating application and database layers, web application firewalls enforcing OWASP protections, intrusion detection, DDoS mitigation, and continuous monitoring with 24/7 alerting. All data is encrypted in transit and at rest, with AES-256 encrypted immutable backups. Access to production systems is managed through zero-trust network controls with multi-factor authentication. Enterprise single sign-on (SSO) integration is supported, with sessions secured by short-lived tokens and OAuth 2.0 protocols. We conduct regular penetration testing aligned to our ISO 27001 programme. Security researchers can report vulnerabilities through our Responsible Disclosure Policy.
Independently Certified
Our security practices are independently audited and certified to the highest international standards.
ISO 27001:2022 — Certified by Bureau Veritas (Certificate DE016539). The global gold standard for information security management.
TISAX AL 2 — Assessed and approved for the automotive industry's stringent information security requirements (Scope S60FFM, Assessment AV20AY-1).
GDPR Compliant — Independently audited with the Cortina Consult DPO seal, confirming full compliance with EU data protection regulations.
View certificates and full details