Security architecture
- Tenant-scoped authorisation, role controls, scoped/revocable API keys, session controls, and audit records for administrative actions.
- TLS on enabled public services, authenticated submission, certificate automation, secret separation, encrypted sensitive exports, and protected credential storage.
- Private service networks, least-privilege database roles, bounded queues, and fail-closed delivery checks in the relevant service components.
- Encrypted off-site backup and recovery tooling, with service launch gated until required monitoring, external probing, recovery, delivery, and abuse evidence is recorded.
Secure operations
The release process requires validated configuration, migration safety checks, health checks, rollback planning, and retained evidence. Operator access should be limited, reviewed, and removed when no longer needed.
Security findings are assessed according to severity and exposure. A service stays behind its release gate while a required finding, test, or operational proof remains open.
Incident response and continuity
Runbooks and monitoring configuration cover service failure, queue growth, delivery reputation, credential compromise, abuse, backup failure, and certificate expiry. Public launch requires proof that independent monitoring, paging, target-host recovery objectives, restoration, and rollback have been tested; an unproven control is not represented as active protection.
Responsible disclosure
Report a suspected security issue privately to support@relaytera.com. Include affected service, reproduction steps, impact, and safe contact details. Do not access other users’ data, disrupt service, send unsolicited traffic, or publish an unremediated issue. The operator will acknowledge and coordinate according to severity once the support operation is activated.