Security
How RelayPDM protects your data.
Each line below describes something the product does, in plain words first and with the technical detail a security reviewer will want. We walk your reviewers through the evidence on request.
Your data is kept apart in the database
Each organization's data is separated by rules inside the database itself (row-level security in PostgreSQL), not by application code. An automated test tries to read, change and move records across organizations on every change we ship.
Roles checked on every request
There are four roles: viewer, member, admin and owner. What each role may see and change is checked by the database every time, not only by the screen in front of you.
An audit log you can export
Changes are recorded with who made them and when. Admins can read the log and export it.
Your data out, any time
Partners, referrals and the audit log export as comma-separated values (CSV) files, which open in Excel or Google Sheets.
Backups we restore, not just take
Backups are kept away from the hosting platform, and we rehearse restoring from them, table by table.
No passwords to leak
You sign in with a one-time email link or with Google. RelayPDM stores no passwords.
Locked down by default
Every connection is encrypted with Hypertext Transfer Protocol Secure (HTTPS). A strict content security policy limits what the page may load, and server keys never reach the browser. Both are checked on every build.
Running a security review?
Send us your questionnaire and we will answer it with the evidence behind each point.