Security
Last updated August 28, 2026
Plain-language summary. Relay is an agent observability product by oprag.ai. This is our current security posture. Enterprise customers can request additional documentation before signing.
Infrastructure
Relay runs on AWS: S3, Cognito, CloudFront, DynamoDB, and Lambda. All environments are operated by oprag.ai — not deployed into customer AWS accounts on Starter or Team.
Tenant isolation
Every agent session, hook event, and transcript is scoped to an organization and workspace. Cross-tenant access is not permitted by architecture.
Encryption
Session data encrypted at rest in S3. TLS in transit. API access via Authorization: Bearer
tokens — treat keys and adapter secrets like passwords.
Authentication
Cognito for Architect dashboard users. API keys and adapter credentials for CLI and programmatic access. Keys are revocable and rotatable from the Architect dashboard.
Session processing
Hook events are ingested and stored within Relay's AWS environment. We do not route your session data to external services outside our managed stack.
What we don't do
- No training on your session data for shared models
- No BYOC / customer AWS deployment on Starter or Team
- No selling or sharing session content with third parties
Reporting
Security concerns → hello@relay.oprag.ai. See also our Privacy page.
Questions? hello@relay.ai