Your data is encrypted, access is limited to the people who need it, and everything we do is logged. Anything touching PHI or PII runs on models inside your own environment, so that data never leaves your walls. We run in a SOC 2 Type II compliant environment and will sign a BAA. The detail below is written for your security reviewer.
Security is foundational to everything we build at Relay Vault. This policy outlines how we protect your data and maintain the highest security standards.
1. Compliance & Certifications
Where we stand on industry-recognized frameworks:
SOC 2 Type II: Our security controls meet SOC 2 criteria for data protection, availability, and confidentiality
HIPAA Compliance: Full compliance with the Health Insurance Portability and Accountability Act
2. AI Models & Data Boundaries
The question we get asked most is which AI sees your data. You draw that boundary, and the architecture enforces it:
PHI and PII never leave your environment: Any workflow that touches protected health information or personally identifiable information runs on open-weight models deployed inside your own cloud tenant, under your controls. That holds for automated workflows running unattended, not just the ones a person is watching.
Fine-tuned models stay yours: Where accuracy benefits from tuning a model on your data, that model is trained in your environment, deployed in your environment, and never shared across customers. Your data is not used to train shared or third-party models.
Frontier models, only outside the boundary: Work that touches no regulated data can use frontier models from the major labs. We hold signed Business Associate Agreements with those providers and operate under zero-retention, no-training terms as a second layer of protection.
Deterministic by design: Our workflows are deterministic. A model is one step inside a defined pipeline, not the thing deciding what happens next. Routing is fixed, each step is explicitly validated, and anything falling outside the rules escalates to a person. Nothing is left to a model to improvise.
Every inference is logged: Which model ran, on what data, in which environment, and with what result. If a reviewer asks whether PHI ever crossed a boundary, the log answers it rather than a policy document.
3. Data Encryption
All data is encrypted at every layer:
In Transit: TLS 1.3 encryption for all data transmitted between systems
At Rest: AES-256 encryption for all stored data
Key Management: Hardware Security Modules (HSMs) for cryptographic key storage and rotation
4. Infrastructure Security
Security is built into every layer of our infrastructure:
Hosted on Aptible, a HIPAA compliant, SOC 2 Type II certified platform, with redundant data centers
Network segmentation and firewalls to isolate sensitive systems
DDoS protection and Web Application Firewall (WAF) for all public-facing services
Continuous vulnerability scanning across employee machines and production assets, with patching within defined SLAs, plus regular penetration testing
Active monitoring and remediation of end-of-life (EOL) software
Immutable infrastructure with automated security patching
5. Access Control
Strict access controls protect your data at every level:
Role-Based Access Control (RBAC): Users only have access to the resources they need
Multi-Factor Authentication (MFA): Phishing-resistant MFA (passkeys, hardware-backed) required for all access to production systems and any platform that stores or processes sensitive data
User-Facing MFA: Users authenticate with MFA before accessing applications that surface financial account connections
Single Sign-On (SSO): Support for SAML and OIDC integration with your identity provider
Audit Logging: Comprehensive logging of all access and actions
Principle of Least Privilege: Employees have minimal access necessary for their role
6. Application Security
Security is integrated throughout the development lifecycle:
Secure coding practices and code review requirements
Static Application Security Testing (SAST) on all code changes
Dynamic Application Security Testing (DAST) in staging environments
Dependency scanning for known vulnerabilities
Regular third-party security assessments and penetration tests
7. Incident Response
Our incident response program includes:
24/7 security monitoring and alerting
Documented incident response procedures with defined escalation paths
Regular incident response drills and tabletop exercises
Commitment to notify affected customers within 72 hours of confirming a security incident
Post-incident review and remediation processes
8. Business Continuity
Continuity of service is ensured through:
Multi-region data replication and failover capabilities
Regular backup testing and disaster recovery drills
Recovery Time Objective (RTO) of 4 hours for critical systems
Recovery Point Objective (RPO) of 1 hour for transactional data
Documented business continuity and disaster recovery plans
9. Employee Security
Every team member is trained and vetted:
Background checks for all employees with access to customer data
Mandatory security awareness training upon hire and annually
Phishing simulations and ongoing security education
Clear security policies and acceptable use guidelines
Immediate access revocation upon employee departure
10. Vendor Security
Vendors are held to the same standards:
Security assessments for all vendors with access to customer data
Contractual security and privacy requirements
Regular review of vendor security posture
Data Processing Agreements (DPAs) with all sub-processors
11. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:
We commit to acknowledging your report within 24 hours and will work with you to understand and resolve the issue promptly. We do not take legal action against researchers who follow responsible disclosure practices.
12. Contact Us
For questions about our security practices or the status of our SOC 2 audit, please contact us: