6 areas
At a glance
The protections that matter to your business.
Start with the outcome. Open the technical detail when you need to see exactly what sits behind it and where a service provider is involved.
01
Identity and workspace access
Protected workspace data requires a verified account and an active workspace profile. Company boundaries and permissions are enforced on the server.
Technical detail+
Authentication and sessions
Service providerA dedicated identity service provides the primary sign-in and session flow. Browser sessions use protected cookies, and workspace access also requires an active, verified profile linked to the signed-in account.
Workspace authorization
RelayBoardAuthenticated requests resolve a workspace profile before protected data is loaded. Workspace data is isolated by company and permissions are enforced on the server. Administrator access is fixed, while supported manager and employee permissions can be tailored by workspace.
02
Credentials and integrations
Stored calendar and webhook credentials are encrypted, while API keys are hashed. Integration access can be scoped, expired, rotated, and revoked.
Technical detail+
Calendar credentials
RelayBoardStored credentials for optional calendar connections are encrypted before storage. This protection applies to the credentials and tokens needed to operate a connection. Calendar data is sent only to the provider a workspace member chooses to connect.
API and webhook credentials
RelayBoardAPI keys are hashed and webhook signing secrets are encrypted before storage. Secrets are shown once. Keys support scoped access, expiry, rotation, and revocation. Outbound deliveries require secure public destinations, are signed for verification, use bounded retries, and keep sensitive values out of delivery logs.
03
Browser and request protection
Restrictive browser policies, origin validation, and request limits reduce exposure to unexpected content, cross-origin changes, and abuse.
Technical detail+
Browser request controls
RelayBoardThe application applies restrictive browser policies and validates where browser changes originate. These controls limit unexpected content, framing, cross-origin changes, information leakage, and access to browser capabilities the product does not need.
Rate limiting
RelayBoardSensitive and resource-intensive routes enforce request limits. Limits cover account access, error reporting, and other abuse-sensitive actions. Deployment checks verify that the required protection is available before the service is considered ready.
04
Payment privacy
Checkout and card details are handled by a billing provider. RelayBoard stores the account references and subscription state it needs, not card numbers.
Technical detail+
Billing boundary
Service providerA billing service provider renders checkout and processes payment details. RelayBoard stores only the account references and subscription state needed to manage access. Card numbers are handled by the billing provider and are not stored by RelayBoard.
05
Careful operational monitoring
Errors and limited operational data are monitored without session recording. Application-added account context is pseudonymous and direct personal information is excluded by default.
Technical detail+
Error monitoring
Service providerA monitoring service receives errors, limited performance traces, and operational logs. Application context is sanitized, direct personal information is excluded by default, and account context is limited to pseudonymous identifiers and role. Session recording is disabled.
06
Export and deletion controls
Workspace administrators can export business data without credentials or billing references, and deletion runs through a retryable provider-cleanup workflow.
Technical detail+
Workspace export
RelayBoardWorkspace administrators can download a portable snapshot of workspace business data. Every exported collection is limited to the administrator's company. Credentials, session material, access codes, connection tokens, and billing references are excluded. Successful exports create a metadata-only audit event and are delivered as private, non-cacheable responses.
Queued workspace deletion
RelayBoardAdministrator-requested workspace deletion runs as a retryable cleanup job rather than an immediate browser action. The job first requests billing cancellation and removes linked identities that are not used by another workspace. If cleanup fails, the workspace remains available for a retry. Provider-managed records may follow separate retention obligations.
Responsibility key
RelayBoardControlled by the RelayBoard application
Service providerHandled with a supporting service provider
Questions welcome
Need a clearer answer?
Security questions and privacy requests can be sent to support@relayboard.app. We would rather explain a boundary plainly than imply a protection the product does not provide.
For how RelayBoard handles information, including provider and retention boundaries, read the Privacy Policy.