Skip to content
Matterhall

For IT and security

Govern the software your employees build with AI.

Matterhall gives employee-built apps and files a secure, centrally managed home, with authenticated access, accountable ownership, and a complete inventory for IT.

Account · Admin

Inventory

Search work or owner
NameStatus
Pipeline reviewPublished
Renewal forecastPublished
Vendor scorecardNeeds review
Onboarding checklistPublished
Churn model notesPrivate preview

The challenge

AI-built applications already exist across your organization.

Blocking AI tools reduces productivity. Ignoring them leaves company data in unreviewed locations. Matterhall provides a governed alternative.

Personal hosting accounts

Publicly accessible by default, billed outside procurement, and lost at offboarding.

Files shared by email and chat

Uncontrolled copies with no version history and no way to revoke access.

Local machines

Unavailable to colleagues and invisible to IT.

Unmanaged cloud projects

Credentials, spend, and company data outside security review.

Remediation

Take action directly from the inventory.

Transfer ownership, review access, or disable an app organization-wide. Changes take effect on the next request, and every administrative action is recorded in the audit log.

Vendor scorecard

Owner needs reassignment
Owner
Chris Obi · Former
Access
Ops workspace · 2 external
Version
v7 · Published Sep 12
Last opened
Yesterday
Transfer owner Review access Disable app

Administration

Every control you need, in one console.

Identity, visibility, and policy enforcement for all employee-built software, without changing how teams build.

  • Single sign-on and automated deprovisioning

    SAML and OIDC with Okta, Microsoft Entra ID, and Google Workspace. Directory sync revokes access when employees leave the organization.

  • Complete application inventory

    Every published app and file, with its owner, access list, and current version, in a single view.

  • Centralized access control

    Revoke access, transfer ownership, or disable any app across the organization. Changes are enforced within 30 seconds.

  • Audit logging

    Every publish, share, permission change, and administrative action is recorded and exportable to your SIEM.

Also included

  • Organization-wide sharing policies
  • Publishing approvals for sensitive content
  • Approved data connections
  • External sharing and ownership alerts
  • Usage and cost reporting by app
  • Per-app budgets and spending limits

Security

Security architecture

Trusted and untrusted content are separated by domain, and every request is authorized at the gateway. Every app and file inherits these controls at publication.

Matterhall request and publishing flowA creator publishes from their tool to Matterhall on matterhall.com. Uploads are quarantined and scanned, then stored privately in the United States. A viewer signs in; the gateway checks permission on every request and serves the content from the separate matterhall.app domain.Trusted · matterhall.comIsolated · matterhall.appCreatorCLI or AI agentViewerAuthenticates firstConsole and APIapp. / api.matterhall.comAuthenticates every userQuarantine and scanMalware inspection beforepublicationPrivate storageus-east1 · never publicAccess gatewayAuthorizes everyrequestPublished app or fileIsolated origin, no accessto Matterhall credentialsuploadopen linkread if allowedserve content
Published content never executes on matterhall.com. Customer applications have no access to Matterhall sessions, credentials, or other tenants’ data.
  • Authenticated access on every request

    Published content is never publicly accessible. The gateway authorizes each request against current permissions rather than once per session.

  • Isolated content origin

    Apps and files are served from matterhall.app, a domain separate from the Matterhall application. Published code cannot access Matterhall sessions or credentials.

  • Malware scanning before publication

    All uploads are quarantined and scanned before they become accessible. Content that fails inspection is never published.

  • Database-enforced tenant isolation

    Every record is bound to its workspace, and PostgreSQL row-level security enforces tenant boundaries independently of application logic.

  • US data residency

    Customer data is stored and processed in Google Cloud’s us-east1 region, including application services, databases, and published content.

  • Encryption and secrets management

    Data is encrypted in transit and at rest. Credentials are stored as protected references and never embedded in published code or logs.

FAQ

Frequently asked questions

What happens when an employee leaves?
Their work remains company property. Directory sync revokes their access, and administrators transfer ownership with links, version history, and access settings preserved.
Is our content used by AI models?
No. Publishing, hosting, and sharing do not send customer content to any AI model, and customer content is never used for model training.
Do we need to standardize on a single AI tool?
No. Matterhall supports output from any tool that produces files or web applications, so teams keep their preferred tools while IT governs the results centrally.
How is pricing structured?
Pricing is per workspace, with hosting included. There are no per-seat or per-viewer fees, so broader adoption does not increase licensing costs.
Can we evaluate Matterhall before a company-wide rollout?
Yes. Most organizations begin with a single workspace for a pilot team. A pilot requires no changes to your identity provider or network configuration.
Will you complete our security review?
Yes. We provide an architecture review, complete security questionnaires, and scope the pilot around your requirements.

Start with a pilot.

We will review the security architecture with your team and scope a pilot for a single department.