Security
Trusted with the
conversations that matter.
Support conversations carry account details, payment questions and identity. Relia treats every one of them as sensitive by default.
SIGNED IDENTITY · TENANT ISOLATED · PERMISSION GATED
Identity
Know who you're talking to.
Relia does not trust spoofable browser identity headers. Customer identity is server-signed before reaching Relia — so platforms can securely connect conversations to real users.
Browser
UNTRUSTED
Your server
SIGNS IDENTITY
Relia
VERIFIES SIGNATURE
user_83a91
signature verified
tenant_acme
- Tenant isolated
- Signed identity
- Publishable browser keys
- Secret server keys
- Permission gated
Built for platforms where support conversations touch money, identity and account access — casinos, fintech, marketplaces.
Multi-tenant architecture
Your infrastructure stays yours.
Every Relia customer operates inside an isolated tenant with their own users, conversations, permissions and keys.
Relia platform
- Customers
- Agents
- Knowledge
- Conversations
- API keys
- Channels
- Customers
- Agents
- Knowledge
- Conversations
- API keys
- Channels
- Customers
- Agents
- Knowledge
- Conversations
- API keys
- Channels
Principles
Security is the architecture, not a page.
Relia is built for platforms where support conversations touch money, identity and account access. These are the properties the system is designed around.
Identity is server-signed
The browser is never trusted. Customer identity is signed with your secret key on your server and verified by Relia before a conversation is linked to a user.
Tenants are isolated
Every query, every index, every key is scoped to a single tenant. There is no cross-tenant code path in the product.
Keys are separated
Publishable keys can open conversations and nothing else. Secret keys stay on your server and can be rotated at any time without downtime.
Access is permission-gated
Owner, admin and agent roles gate every action in the inbox and the API. Escalation paths are explicit, and access changes are logged.
Transport is encrypted
All traffic between the widget, your servers and Relia runs over TLS. Webhook deliveries are signed so you can verify origin.
AI stays inside your knowledge
The AI answers only from your own sources, and every answer records which documents it used. Below the confidence threshold, a human takes over — by design.
Your data stays yours
Export conversations, customers and knowledge through the API at any time. Deletion requests cascade through messages, attachments and search indexes.
Disclosure is welcome
Found something? security@relia.gg reaches the engineers who can fix it. We respond to every report.
Questions about compliance requirements for your platform? Talk to us before you integrate.
Integrate with confidence.
Read how identity signing works, then wire it up in the docs.