Security and trust

Give Relay access without giving up control.

Relay is designed around scoped identity, separated organizations, revocable connections, explicit permissions, human approval, and visible activity.

Keep your CRMStart with one jobApprove what matters
01

Identity and sessions

Google and Microsoft OpenID Connect use state, nonce, and PKCE validation. Relay stores revocable hashed sessions, not identity-provider passwords.

02

Organization boundaries

Each active session is pinned to one organization. Membership and permissions are checked before organization data is read or changed.

03

Connector access

Provider credentials and application secrets remain server-side. Connections can be scoped and revoked through Relay and the provider.

04

Approval controls

Messages, publishing, purchases, deletion, commercial changes, and other sensitive work can wait with the exact consequence visible.

05

Activity history

Relay records the actor, source, policy, time, provider result, and recovery path for executed work.

06

Execution safety

Stable request keys, retries, stop conditions, and provider-aware runners help prevent duplicate or out-of-policy action.

Early-access trust status

Specific about what exists. Honest about what comes next.

Relay does not publish certification, compliance, uptime, or model-training claims that have not been completed and documented.

Available now

Scoped authentication, organization permissions, server-side secrets, approval policy, and attributable activity.

Before broader launch

Formal subprocessors, retention details, model-provider policy, trust materials, and any verified compliance roadmap.

Control in practice

The safest connection is the smallest useful connection.

Begin with one workflow, connect only the tools it needs, review the available read and write capabilities, and keep consequential actions behind approval.

01

Choose one job and its minimum required data.

02

Review provider scopes and organization permissions.

03

Test with approval before expanding autonomy.

Start small

Start with a workflow whose boundary is easy to see.

Connect only the tools that job needs. Set the approval boundary. See the result before expanding.