Ordermatrix is an early-stage product, and we believe in being honest about what's in place — and what's still on the roadmap.
All traffic to Ordermatrix is served over HTTPS with TLS. Your customer data, addresses, and payments are encrypted between your browser and our servers.
JWT-based authentication with secure password hashing (bcrypt). Tokens are scoped per tenant and expire on logout. Multi-factor authentication is on our roadmap.
Within your account, you control who sees what. Roles like sales, dispatcher, and admin restrict access to sensitive operations like deleting orders or viewing payment reports.
We never store your customers' card numbers or UPI credentials. All payment processing is handled by Razorpay, which is PCI-DSS compliant. We only store payment status and reference IDs.
Hosted on Vercel (frontend) and Railway (backend). Database on MongoDB Atlas with encryption at rest. Files on Cloudflare R2. Industry-standard cloud providers, not a server under someone's desk.
MongoDB Atlas runs automated backups. Your data is recoverable in case of accidental deletion or infrastructure issues. Point-in-time recovery available on higher tiers.
Everything you enter into Ordermatrix — customers, orders, payments, notes — belongs to you. Full stop.
You can export your data anytime, in CSV. If you cancel your subscription, we keep your data accessible for 90 days so you can export it before deletion.
We don't sell, share, or use your customer data for any purpose other than running your account. We don't train AI models on it. We don't show it to advertisers.
We're an early-stage product. We don't have SOC 2 certification. We don't have ISO 27001. We don't have a third-party penetration test report to share.
What we do have: honest engineering practices, a small team that takes security seriously, and the same cloud infrastructure most modern SaaS products run on.
As we grow, certifications will follow. We'll update this page when they do — not before.
If you've discovered a vulnerability, please report it responsibly. We take every report seriously and will respond within 48 hours.
[email protected]For data handling specifics and your rights: