Security

Last updated: 1 May 2026 · An honest description of what we have in place, what is in progress, and what is still planned. We do not claim certifications we have not earned.

Honest disclosure: Relay is not currently SOC 2 certified, ISO 27001 certified, or penetration-tested by a third party. Where a control is not yet in place, we say so on this page.

Encryption

TLS 1.2+ in transitIn place

HTTPS on every external connection. HSTS preload eligible.

AES-256 at restIn place

Supabase managed Postgres + Storage encryption at rest.

App-layer encryption for tokensIn place

WhatsApp + Gmail OAuth tokens encrypted with AES-256-GCM before write.

Authentication & access

Supabase AuthIn place

Email/password with bcrypt-style hashing. Magic link supported.

MFA for the operatorIn place

Required on Supabase, Vercel, Stripe, GitHub, Cloudflare, Resend admin consoles.

Row-Level Security on every tableIn place

No agent can read another agent's data. Agency RLS is opt-in and gated by role.

Role-based agency access (RBAC)In place

KEO > Admin > Agent. KEO-only routes for compliance and SSO config.

SAML SSO for agenciesIn progress

Behind RELAY_SSO_ENABLED feature flag. Per-agency provider id, domain match in /login.

Quarterly access reviewsPlanned

Formal review cadence + signoff. Currently ad-hoc.

Logging & audit

CEA-grade audit logIn place

Every AI draft, send, score, stage change, lead create/delete recorded with 5-year retention.

System health logIn place

Per-service ping log feeds the public 30-day uptime number on /status.

Centralised security log reviewIn progress

Currently spot-checked. Routine weekly review cadence not yet formalised.

Operational

Daily encrypted backupsIn place

Supabase daily backup, same Singapore region. Tested restore once per quarter.

Incident response runbookIn place

Internal doc covering breach notification timeline (PDPA: within 3 days of assessing notifiability).

Vendor management programmeIn progress

Sub-processor list maintained. Formal annual vendor review not yet scheduled.

Secrets managementIn place

Server-only env vars on Vercel + a secrets vault for shared credentials.

External assurance

Penetration testingPlanned

Scheduled Q3 2026 with an external CREST-accredited testing firm. Not yet performed.

SOC 2 Type I readinessIn progress

Internal gap analysis live (KEO-only inside the app). Engagement with an auditor planned for H2 2026. Relay is NOT SOC 2 certified.

ISO 27001Planned

Not pursued. We will say so honestly until that changes.

Reporting a vulnerability

Email [email protected]. We acknowledge within 1 business day. We do not have a paid bug bounty programme yet — but we credit responsible disclosures publicly with the reporter's permission.

More detail

This document was prepared by Relay's product team and is not a substitute for legal advice.