Security Overview
Security is core to how Relai is built. Because Relai speaks to your customers on your behalf and works inside your CRM, we design for least privilege, keep your CRM as the source of truth, and are careful about how data flows to the services that power the platform. This page summarises the technical and organisational measures we use.
1. Overview
We combine encryption, least-privilege access, careful data-flow design, and vetted subprocessors to protect your data across every channel Relai touches — WhatsApp, email, phone and your CRM. The sections below describe how, and who to contact if you have questions or need a security review.
2. Data encryption
All traffic between your browser, the Service and our integrations is encrypted in transit using industry-standard TLS. Data at rest is stored on Amazon Web Services (AWS) infrastructure with encryption at rest. Credentials are never stored in plain text — passwords are protected with a salted, computationally-hard hash (scrypt), and secrets and API keys are held in protected configuration, never in source control.
3. Access control
Access to the Service is authenticated and governed by roles. Everyday users, administrators and platform operators have different, least-privilege permissions. Notably, the platform-operator role — used to manage accounts and billing metadata — is designed not to have access to any tenant's contacts or conversation content, keeping account administration separate from customer data. Internal access to production data is limited to personnel who need it to run and support the Service, and is subject to confidentiality obligations.
4. Your CRM stays the system of record
Relai reads from and writes back to your existing CRM, which remains your authoritative store of contact data. This limits duplication of personal data and means much of it stays within systems you already control and can govern directly.
5. AI data handling
Relai uses large language models (via Anthropic) to generate messages and insights. Content sent for AI processing is transmitted securely and, under Anthropic's commercial API terms, is not used to train their models. Relai does not use your data to train any third party's models. The platform is designed to keep a human in control of consequential actions, with a review-before-send option and clear guardrails that make the AI escalate what it cannot answer rather than guess.
6. Messaging compliance
WhatsApp messaging runs on the official WhatsApp Business Platform (through our Business Solution Provider), honouring opt-in, approved templates and per-recipient sending tiers. The platform automatically self-throttles to a safe fraction of the available daily volume and responds to quality-rating changes, protecting your messaging reputation.
7. Infrastructure and network
The Service is hosted on reputable cloud infrastructure (Amazon Web Services (AWS), UK/EU region) with network controls, isolation between environments, and regular patching. Administrative access to infrastructure is restricted and authenticated.
8. Subprocessors
We rely on a small set of established subprocessors (listed in our Privacy Policy and DPA), each engaged under contracts requiring appropriate security and data-protection commitments. We review new subprocessors before onboarding them.
9. Logging and monitoring
The Service maintains an append-only activity log of what the AI does across each agent and channel, supporting traceability and investigation. Operational logs help us detect and respond to anomalies and abuse.
10. Backups and resilience
We take regular backups of platform data to support recovery. Backup frequency and recovery objectives are being formalised as the platform scales.
11. Secure development
Changes are reviewed before release, secrets are kept out of source control, and dependencies are monitored and updated for known vulnerabilities. Access to code and infrastructure is limited and authenticated.
12. Incident response
We maintain an incident-response process to contain, investigate and remediate security incidents, and — where a personal data breach affects customer data — to notify affected customers without undue delay in line with our DPA.
13. Responsible disclosure
If you believe you have found a security vulnerability, please report it to security@relaioffice.com. We appreciate responsible disclosure and will work with you to resolve valid issues promptly. Please do not access or modify data that is not yours, or disrupt the Service.
14. Your part in security
Security is shared. Please keep your credentials confidential, use strong passwords, manage your users' access, review AI output before relying on it, and ensure you have the consents needed to contact your leads and record calls.
15. Compliance and certifications
We operate in line with UK and EU GDPR and support customers with a Data Processing Agreement. Lion’s Point Ltd does not currently hold SOC 2 or ISO 27001 certification. Our infrastructure runs on Amazon Web Services (AWS), whose data centres are independently certified to standards including SOC 2 and ISO 27001; we can pursue our own formal certification as customer requirements grow. For security questionnaires or more detail, contact security@relaioffice.com.