Security

Honest by design.

We say plainly what each tier guarantees, and we never dress an access rule up as a cryptographic one. Trust isn't a switch — it's a ladder, and we tell you which rung you're standing on.

Custody

A hand-off that actually lets go.

Most sharing is a copy that never leaves you. Relay records the difference. Share a relay and you both hold it; transfer custody and it leaves your hands — you keep the receipt, not the contents. Either way, which one happened is a recorded fact, not a claim.

Shared
relayed in · you still hold it
The everyday case: the next holder gets the context, you keep yours, the trail shows both.
Custody moved
transferred · receipt kept
It leaves your hands. You keep proof you sent it — who, when, what — without keeping the contents.
Spent
single-use · relayed in once
A single-use Code is spent on first use. The default, because a handoff should be one clean pass.
Expired
time or choice
Codes can carry an expiry, and a sent relay can be revoked or recalled before it's relayed in.
The ladder

Each rung removes a reader.

L1 · Hardened service — today
Only authorized users.
Encrypted in transit and at rest, consent-gated sharing, full trail. We operate the service, and we say so: on this plane we are a trusted operator, not a zero-knowledge one.
L2 · Per-tenant keys — today
One leak is never everyone.
Tenants are cryptographically separated, so exposure doesn't cascade.
L3 · You hold the keys — sovereign
The vendor cannot read.
Your keys, your tenancy, your region. For the orgs that cannot extend trust to any operator — a deployment choice, not a different product.
L4 · Zero-knowledge — narrow opt-in
No one but you.
The top of the ladder, scoped deliberately. We'll claim it where it's true and nowhere else.
Six questions

The whole posture.

Authorization
Who can touch it?
Content release is explicit: the author, a grant, an opted-in connection, or a prior approval. Org membership grants no reads, and being an admin never quietly means being a reader — org policy can restrict a relay, never auto-approve one.
Custody
Does it leave your hands?
Shared, transferred, spent, expired — the state is recorded, so "custody moved" is a provable fact.
Containment
Who could ever read it?
The ladder, stated per tier. Stronger guarantees exactly where the deployment supports them, and never claimed where it doesn’t.
Residency
Where do the bytes live?
Object storage is region-aware and fails closed: an unconfigured region refuses the write rather than quietly crossing a border. Relay content itself is not region-pinned yet, and we say so until it is.
Provenance
Can you prove who held it?
Who created, who took it in, who forwarded — every hop timestamped, coupled to the write itself.
Honesty
Does the promise match reality?
Per tier, in writing. The strongest security claim we make is the one we can keep on the rung you're on.
Compliance

In progress, and said plainly.

Relay is in Early Access. SOC 2 and independent penetration testing are on the near-term roadmap, not yet certified — we won't claim a badge we haven't earned. Payments run through Stripe; we don't store card data. Want our current security posture or data-handling details? Ask and we'll share them.

SOC 2 · plannedPen test · plannedDPA · on request

Context in.
Context out.

Governed, attributable, and honest about which rung you’re on. Join the Loop and put it to work.

Join Relay
Registration is open — access by activation code as Early Access expands.