Security

Built for conversations where there's no room for "oops."

Matrix moves real value. The security model assumes that, everywhere: typed plans instead of free-form actions, simulation before signatures, keys that never leave your wallet, and an audit trail by construction.

Trust center Responsible disclosure
The gate

Simulation before signature

Every plan is replayed against forked live state and checked against your guardrails — spend caps, allow-lists, slippage, time windows. Failing plans are discarded unsigned and unbilled.

Keys

No custody, ever

Auth is ed25519 DID through Paxport; signing is EIP-712 from your wallet or a scoped agent session. Matrix never holds key material.

Determinism

The type system is the perimeter

A closed verb vocabulary and version-pinned tools mean reachable behavior is enumerable. The planner proposes; the schema rejects anything else.

Isolation

Scoped, expiring sessions

Agent sessions scope down from declared capabilities, expire by default, and are revocable instantly. Runtime surfaces are origin-validated and provenance-checked.

Assurance

Independently audited, continuously hardened

The Matrix codebase undergoes external security review, and findings are remediated and verified before release milestones. We publish audit summaries and remediation status in the Trust Center, and run a standing disclosure program.

Read the latest audit summary →
assurance
External audit — remediations verified
Auth hardening — token & session review
Runtime origin validation across surfaces
Dependency & CVE patch cadence — weekly
Posture
AreaApproach
Identityed25519 DID (Paxport) · EIP-712 signing · JWT hardened
Executiontyped IR · closed verbs · version-pinned tools
Pre-flightdeterministic simulation · guardrail profiles
Audit trailplans, sims, signatures, receipts — replayable
ComplianceGDPR · CCPA · MiCA-aligned · Delaware (PaxLabs Inc.)
Disclosuresecurity@matrix.paxeer.network · safe harbor

Trust, then verify. Then verify again.

Join the limited release Next: the network →