Security

Trusted with the
conversations that matter.

Support conversations carry account details, payment questions and identity. Relia treats every one of them as sensitive by default.

SIGNED IDENTITY · TENANT ISOLATED · PERMISSION GATED

Identity

Know who you're talking to.

Relia does not trust spoofable browser identity headers. Customer identity is server-signed before reaching Relia — so platforms can securely connect conversations to real users.

Browser

UNTRUSTED

Your server

SIGNS IDENTITY

Relia

VERIFIES SIGNATURE

user_83a91

signature verified

tenant_acme

  • Tenant isolated
  • Signed identity
  • Publishable browser keys
  • Secret server keys
  • Permission gated

Built for platforms where support conversations touch money, identity and account access — casinos, fintech, marketplaces.

Multi-tenant architecture

Your infrastructure stays yours.

Every Relia customer operates inside an isolated tenant with their own users, conversations, permissions and keys.

Relia platform

Tenant Aisolated
  • Customers
  • Agents
  • Knowledge
  • Conversations
  • API keys
  • Channels
Tenant Bisolated
  • Customers
  • Agents
  • Knowledge
  • Conversations
  • API keys
  • Channels
Tenant Cisolated
  • Customers
  • Agents
  • Knowledge
  • Conversations
  • API keys
  • Channels

Principles

Security is the architecture, not a page.

Relia is built for platforms where support conversations touch money, identity and account access. These are the properties the system is designed around.

Identity is server-signed

The browser is never trusted. Customer identity is signed with your secret key on your server and verified by Relia before a conversation is linked to a user.

Tenants are isolated

Every query, every index, every key is scoped to a single tenant. There is no cross-tenant code path in the product.

Keys are separated

Publishable keys can open conversations and nothing else. Secret keys stay on your server and can be rotated at any time without downtime.

Access is permission-gated

Owner, admin and agent roles gate every action in the inbox and the API. Escalation paths are explicit, and access changes are logged.

Transport is encrypted

All traffic between the widget, your servers and Relia runs over TLS. Webhook deliveries are signed so you can verify origin.

AI stays inside your knowledge

The AI answers only from your own sources, and every answer records which documents it used. Below the confidence threshold, a human takes over — by design.

Your data stays yours

Export conversations, customers and knowledge through the API at any time. Deletion requests cascade through messages, attachments and search indexes.

Disclosure is welcome

Found something? security@relia.gg reaches the engineers who can fix it. We respond to every report.

Questions about compliance requirements for your platform? Talk to us before you integrate.

Integrate with confidence.

Read how identity signing works, then wire it up in the docs.