Security & data flow
The eight questions a committee asks before approving a pilot — answered plainly, including the parts that are still in progress.
Who owns the member relationship?
The institution — always. Relay is invisible infrastructure behind your brand. Members never create a 'Relay account'; they arrive through your home banking and your support desk stays first contact.
Where does the data live?
In your environment or your approved hosting. Core banking data is never copied to Relay — accounts, balances and transactions are referenced through your API layer with member permission. Relay stores only profile, preference and organization data.
Who is responsible if a helper pays the wrong bill?
No payment executes on a helper's action alone. Helpers prepare; the account holder (or a designated approver) approves. Money movement itself happens inside your existing bill-pay system, under your existing policies and liability framework — Relay never moves money.
Who can prepare vs. submit a payment?
Roles are explicit: viewers see balances, helpers can prepare payments and organize information, approvers (the member) release anything that touches money. Every grant is per-person, per-permission and revocable at any time.
Is there an audit trail?
Every helper action — views, preparations, approvals, invitations, permission changes — is written to an append-only audit log with actor, timestamp and scope. Institutions can review the full history of any relationship.
How are documents protected?
Documents live in institution-approved storage, encrypted in transit and at rest, referenced by Relay rather than copied. Access follows the same role-based permissions as everything else, and every view is logged.
What is the retention policy?
Set by the institution. Member data is deleted or returned on contract end; audit history retention is configurable to your records policy. Relay claims no rights over member data.
What is your compliance status?
Relay is built to a SOC 2-aligned control set (access control, audit logging, encryption, change management). We do not yet hold a SOC 2 report — we will tell you exactly where we stand, and pilot partners get our full control documentation under NDA.
Demonstration environment. This page describes the production security architecture Relay deployments are built to. The demo you are viewing uses simulated connections and local sample data — no real member, account or document data is present. See the integration setup or review plans.