Security at Relways
A concise overview of safeguards for the public site and early-access request flow.
Relways limits the public data surface, protects administrative access, and removes records according to defined retention periods.
Public-site safeguards
The public site uses HTTPS, restrictive browser security headers, request validation, and rate limits.
- Administrative and setup routes are not exposed on the public host.
- Analytics uses a session-only identifier rather than a persistent visitor ID.
- The form warns against submitting sensitive information.
Administrative access
The owner review area is separate from the public site and requires authenticated access with a second factor.
- Administrative changes require session and request-integrity checks.
- Export and deletion tools are restricted to the owner area.
- Expired public-site records are removed by a scheduled lifecycle process.
Report a concern
Send security reports to hello@relways.com or use the contact published in /.well-known/security.txt.
- Describe the affected page and a safe reproduction path.
- Do not include credentials, secrets, or customer records in the first message.
- Relways does not claim security certifications or independent audits.
Report a security concern
Send a concise description without customer data or credentials.
