Security

How Relay protects your account, data, and keys.

Sessions: sign-in uses secure, HTTP-only session cookies. OAuth is handled by established providers — we never see your Google password.

Passwords: email-password credentials are stored as salted scrypt hashes, never in plain text.

API keys: keys you add under Settings are encrypted at rest with AES-256-GCM and are only ever decrypted inside server code when calling models on your behalf. Our own API routes never return a key — only a short hint.

Transport and storage: traffic runs over TLS, and database access is restricted to the application. Contact messages and billing records live alongside your account data and inherit the same protections.

What we ask of you: use a strong unique password, keep your own provider keys private, and report anything suspicious to support@relay.app.

Disclosure: if you believe you've found a vulnerability, tell us first at support@relay.app and give us reasonable time to fix it before any public disclosure.