Security and trust

Important context deserves strong boundaries.

Relaite is being designed around explicit access, strong tenant isolation, encryption, source-aware visibility, bounded AI processing and human control.

Understanding more about work must not mean making information more broadly accessible.

THE SECURITY BOUNDARY

Authorise deliberately.

Retrieve selectively.

Preserve visibility.

Keep evidence inspectable.

Keep people in control.

Microsoft 365 connection

Clear about what is connected.

When you connect Microsoft 365, Relaite requests delegated, read-only access to the email and calendar information required by the features you enable.

The final permission list is shown during Microsoft consent. Relaite does not request permission to send email, modify messages or change calendar events for initial deployments.

INTENDED INITIAL MICROSOFT SCOPES
Identityopenid · profile · email
Continued authorised accessoffline_access
EmailMail.Read
CalendarCalendars.Read

Additional permissions will only be requested when a specific feature requires them.

Data scope

Metadata first. Content when the feature requires it.

What Relaite derives

People, organisations, relationship history, initiatives, meetings, decisions, commitments, dependencies and recommended next actions.

What Relaite processes

Authorised message and calendar metadata first. Message bodies and attachments are retrieved according to workspace scope and enabled features.

What disconnecting means

Disconnecting a source stops further synchronisation. Production controls are being designed for source deletion, workspace deletion, export and retention policies.

Derived context

AI should not silently rewrite organisational reality.

Relaite is being designed to distinguish between source evidence and the context derived from it.

The production architecture is being designed so that important derived context can retain these properties.

01

Source references

The communication or meeting supporting the claim.

02

Confidence

How strongly the available evidence supports the interpretation.

03

Observation time

When the source was observed and when the claim was produced.

04

Processing version

Which product logic produced the interpretation.

05

Visibility

Who may access the source and derived context.

06

Review and correction

Whether a person reviewed, changed or rejected the claim.

This supports inspection, correction and replay as the product improves.

Control model

Security follows the information.

01

Explicit, read-only access

Each Microsoft 365 mailbox must be deliberately authorised. Initial deployments request delegated, read-only access and cannot send email or change calendar events.

02

Strong tenant boundaries

Every request is resolved to a verified user, tenant and role. Customer records, source objects, search entries and processing jobs remain scoped to that tenant.

03

Least-privilege services

Each application service receives only the AWS permissions required for its function. Processing workers do not receive general access to connection credentials or infrastructure.

04

Encrypted by design

Customer data is encrypted in transit and at rest. Production is designed to use customer-managed KMS keys, with Microsoft OAuth tokens protected by a separate key.

05

Permission-aware AI

Relaite retrieves selected context for a specific task. AI does not receive unrestricted mailbox access or widen what a user is authorised to see.

06

Inspectable activity

Authentication, administrative changes, access failures, key use and deletion workflows produce security records without copying customer communication into ordinary logs.

Continuity and visibility

Context should not become more public because it became useful.

Information needed for continuity may originate from private, mailbox, team or tenant sources. Derived context should preserve those boundaries.

A useful relationship brief is not permission to expose every source used to construct it.

INFORMATION VISIBILITY
01Private
02Mailbox
03Team
04Tenant

Derived context retains the visibility of its sources. Private information cannot silently become tenant-wide knowledge.

Tenant authorisation

A tenant identifier is not proof of access.

Application identity and Microsoft consent are separate. API requests are authenticated, resolved to a verified workspace and checked against authoritative membership before customer data is accessed.

Storage keys, objects, derived claims and retrieval indexes carry their tenant scope. Sensitive operations can revalidate current membership rather than relying only on a previously issued token.

AUTHENTICATED USERVERIFIED WORKSPACEAUTHORITATIVE MEMBERSHIPAUTHORISED DATA SCOPE

Application and infrastructure

Serverless infrastructure. Explicit application responsibility.

AWS operates the physical infrastructure, host operating systems and managed service platforms. Relaite remains responsible for secure code, dependencies, tenant isolation, IAM, encryption configuration, retention, monitoring and incident response.

CLOUDFRONT + WAFPlanned application edgeCOGNITO + API GATEWAYIdentity and authenticated requestsSERVERLESS SERVICESBounded roles and processing stagesDYNAMODB + PRIVATE S3Tenant-scoped encrypted data

Encryption at rest

Control over the keys.

DynamoDB encrypts records, indexes, streams and backups. Production is designed to use a customer-managed data key. Raw and derived content is stored in private, encrypted S3 buckets.

Microsoft OAuth refresh tokens use a separate KMS key and an encryption context tied to the tenant and mailbox.

IAM least privilege

Only the access a service needs.

Connector, API, processing and deployment responsibilities are separated. Token decryption is restricted to the connector path, and production access is separated from development and ordinary user access.

Logging and auditability

Evidence without copying the inbox.

Security logging covers authentication, failed authorisation, administrative activity, IAM and KMS changes, deployments, processing failures and deletion workflows.

Email bodies, attachments, OAuth tokens, secrets and full prompts are excluded from ordinary application logs.

Bounded AI

Selected context, not an open mailbox.

Relaite resolves the user, tenant, visibility and task before retrieving sources for inference. Amazon Bedrock does not share customer inputs with model providers or use them to train foundation models.

Initial deployment boundary

Relaite can recommend. A person decides.

Initial production deployments are read-only. Relaite does not contact customers or modify connected business systems. Future external actions will require explicit enablement, narrow permissions, user approval and an audit record.

Current status

Built openly, claimed carefully.

The production security architecture is being developed and validated for design-partner deployments. The controls described here represent the intended production boundary. Implementation status and pilot-specific controls will be documented during security review.

Relaite does not currently claim SOC 2, ISO 27001 or other security certification.

Discuss a design-partner pilot