Security

How We ProtectYour Messages

A message is locked on the device that sends it and opened only on the devices meant to receive it. Everything in between handles a sealed envelope, your own server included.

A shield and fingerprint

What End-to-End Encryption Means

Many platforms encrypt traffic in transit and at rest, which stops anyone reading it off the wire. The vendor can still read it, because the keys are held on their side.

End-to-end means the keys live on the devices, so there is no key on a server to disclose.

Encryption Built for Groups

Encryption at group scale

Relay encrypts every message, voice note and file in a channel of hundreds exactly as it does in a one-to-one thread, including as members join and leave.

Access is bounded by membership

A member who joins on Tuesday cannot read Monday's messages, and a member who leaves on Friday cannot read Saturday's.

Account data is encrypted as well

Encryption extends to account records, so a stolen copy of the database does not reveal who your contacts are.

Security Beyond Encryption

Most incidents aren't a broken cipher. They're a laptop in a taxi and an account nobody closed.

Every session, listed and revocable

See every device signed in to an account, and cut off any one of them.

Permissions by role

Who creates channels, who invites, who may reach outside — set once for a role.

An administrative record

Administrative actions are logged, so “who changed that, and when” has an answer.

Joining and leaving stay one process

Connect the directory you already run, so an account ends when the employment does.

Start Now

Have Your Security Team Read It

We'll walk your security officer through the deployment, the key handling and the console, on a trial hosted by us or standing on your own hardware.

A globe drawn as a dot matrix