Security and protection
How Mattr separates workspaces, protects command execution and checks access to files, projects and connections.
Workspace isolation
Each workspace has its own members and data. The server verifies membership and associates each request with a workspace. Access to one workspace does not grant access to another workspace's files, conversations, projects or applications.
Free and Pro use shared infrastructure with logical separation of data and permissions. Team gets a separate server. Enterprise deployment in the customer's infrastructure is governed by the contract.
For choosing and switching workspaces, see workspaces.
Personal and shared materials
Mattr distinguishes between personal user files, shared workspace files, assistant knowledge and materials belonging to conversations, projects and applications. When files are accessed, the server checks their access scope.
- A regular conversation is associated with a workspace, user and assistant.
- For a project, user membership and assistant assignment are checked.
- For an application, viewing and editing permissions are checked separately.
- Shared materials are available to members within their permissions. Project members can work in the project's shared working area.
Before storing a document, check who should have access: just you or the team. See working with files and managing members.
Isolated command execution
In server mode, assistant commands run in containers associated with a workspace and working area. Users' personal working areas are separated. This does not mean a separate container for every message: tasks in the same working area may share an environment.
The container filesystem is read-only except for designated working and temporary directories. Additional system privileges are disabled, and privilege escalation is prohibited. Direct container network access is disabled in the standard server configuration. Shared server infrastructure enforces limits on resources and concurrent runs.
Keys and connections
Secrets in Mattr's storage are encrypted using AES-256-GCM and belong to their owner or workspace. Enter keys in the settings intended for them, not in normal assistant messages.
When connecting a service, check the selected account and requested permissions. Inviting a colleague to a workspace does not itself connect their personal services. If a connection is no longer needed, disconnect it in Mattr and revoke permissions in the external service where necessary.
See connections for the steps.
Data storage and model requests
Mattr cloud account databases and user files are hosted on servers in Russia. When a task runs, the model provider may receive the request text, selected files and context. A connected external service also receives the data needed for the action assigned to it.
Working environment isolation does not mean model requests never leave that environment. Before working with company documents, consider the company's rules for sending data to external services.
Report a security issue
Email support@mattr.ru. Explain which action caused the issue and when it occurred. Do not attach passwords, API keys or other people's documents. If you suspect an external service key has leaked, revoke it in that service and update the connection.