Security Policy

Effective Date: August 24, 2026

The short version

Your data is encrypted, access is limited to the people who need it, and everything we do is logged. Anything touching PHI or PII runs on models inside your own environment, so that data never leaves your walls. We run in a SOC 2 Type II compliant environment and will sign a BAA. The detail below is written for your security reviewer.

Security is foundational to everything we build at Relay Vault. This policy outlines how we protect your data and maintain the highest security standards.


1. Compliance & Certifications

Where we stand on industry-recognized frameworks:


2. AI Models & Data Boundaries

The question we get asked most is which AI sees your data. You draw that boundary, and the architecture enforces it:


3. Data Encryption

All data is encrypted at every layer:


4. Infrastructure Security

Security is built into every layer of our infrastructure:


5. Access Control

Strict access controls protect your data at every level:


6. Application Security

Security is integrated throughout the development lifecycle:


7. Incident Response

Our incident response program includes:


8. Business Continuity

Continuity of service is ensured through:


9. Employee Security

Every team member is trained and vetted:


10. Vendor Security

Vendors are held to the same standards:


11. Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:

security@relayvault.ai

We commit to acknowledging your report within 24 hours and will work with you to understand and resolve the issue promptly. We do not take legal action against researchers who follow responsible disclosure practices.


12. Contact Us

For questions about our security practices or the status of our SOC 2 audit, please contact us:

security@relayvault.ai

Relay Vault, LLC

San Francisco, CA