Security

Conversations are
private by default,
shareable on purpose.

Reline (reline.so) is built around a single rule: nobody sees what you record unless you grant access, and every grant is logged. Here is how the permission model, encryption and audit log work.

Pillars

Six pillars, one promise.

Encryption in transit & at rest

TLS 1.2+ on every request. AES at rest in the database. Audio archive blobs are stored in Cloudflare R2, also encrypted at rest.

SSO via WorkOS

Auth ships Google and Microsoft OAuth out of the box, and SSO (Google + Microsoft) is available on request for Enterprise organizations.

Five-level permission model

Workspace · teamspace · folder · note. Each level has owner / admin / member roles, and every note can also carry per-user, per-teamspace, or per-workspace overrides.

Append-only audit log

Per-note activity (share, edit, restore, access grant) is logged on every plan in `noteActivity`. On Enterprise, a workspace-scoped audit log adds membership, settings, teamspace, and policy-decision events. Both logs are append-only.

No silent training

Your audio and transcripts are never used to train third-party models. AI providers receive prompts via the AI SDK gateway and return completions — no upstream retention beyond their own policies.

US-hosted infrastructure

Your data is hosted in the United States: Convex serves the database and Cloudflare R2 stores recordings and files. An EU region is on the roadmap for enterprise customers — ask during procurement.

Posture

What’s live, what’s in progress, what’s next.

A live posture matrix. We update it the moment status changes — no embellishment.

ControlStatus
Encryption in transit (TLS 1.2+)Live
Encryption at restLive
SSO via WorkOS — Google · MicrosoftLive
SAML SSO (generic / Okta) — on the roadmapPlanned
Audit log: per-note (all plans) + workspace-scoped (Enterprise)Live
Per-note access requests with expiryLive
Outbound webhook signingLive
SOC 2 Type II — on the roadmapPlanned
GDPR data subject access (DSAR)Live
SCIM provisioning — on the roadmapPlanned
HIPAA BAA — not currently availablePlanned

We don’t claim certifications we don’t have. The matrix above is the source of truth — if a row flips to “Live”, we publish a changelog entry and update this page the same day.

Report a vulnerability

Coordinated disclosure. Email security@reline.so with a description and a way to reach you. Bounties for high- and critical-severity reports.

Documentation

Privacy policy, sub-processor list and data processing addendum are public. A summary of our incident response process is available on request.

Workspace controls

As an admin, configure SSO, manage member roles, audit access events, and rotate workspace tokens — all without a CSM.

Need a SOC report or signed DPA before procurement?

There is no SOC 2 report today. We share our security documentation under NDA and sign the DPA on request.

Talk to security