Skip to content
RelayPDM

Security

How RelayPDM protects your data.

Each line below describes something the product does, in plain words first and with the technical detail a security reviewer will want. We walk your reviewers through the evidence on request.

  • Your data is kept apart in the database

    Each organization's data is separated by rules inside the database itself (row-level security in PostgreSQL), not by application code. An automated test tries to read, change and move records across organizations on every change we ship.

  • Roles checked on every request

    There are four roles: viewer, member, admin and owner. What each role may see and change is checked by the database every time, not only by the screen in front of you.

  • An audit log you can export

    Changes are recorded with who made them and when. Admins can read the log and export it.

  • Your data out, any time

    Partners, referrals and the audit log export as comma-separated values (CSV) files, which open in Excel or Google Sheets.

  • Backups we restore, not just take

    Backups are kept away from the hosting platform, and we rehearse restoring from them, table by table.

  • No passwords to leak

    You sign in with a one-time email link or with Google. RelayPDM stores no passwords.

  • Locked down by default

    Every connection is encrypted with Hypertext Transfer Protocol Secure (HTTPS). A strict content security policy limits what the page may load, and server keys never reach the browser. Both are checked on every build.

Running a security review?

Send us your questionnaire and we will answer it with the evidence behind each point.

Email hello@relaypdm.com