VisiRelay
Menu

Security

Template: requires legal review

This is a working draft for a pre-launch product. It hasn’t been reviewed by counsel, does not guarantee compliance in any jurisdiction, and bracketed fields are still incomplete.

This page describes the controls built into the product. It is not a certification. VisiRelay has not been independently audited or certified (e.g. SOC 2, ISO 27001) as of the date above.

Tenant isolation

Each organization is a separate tenant. Database row-level security restricts every query to the current tenant, set per transaction, and the application connects with a role that cannot bypass it. Brand-level permissions restrict which client workspaces a user can see. Automated tests attempt cross-tenant and cross-brand access.

Authentication

  • Passwords hashed with argon2id; login and reset are rate-limited.
  • Sessions use httpOnly cookies with server-side revocation; CSRF protection on state-changing requests.
  • Multi-factor authentication available for administrators [status at publish time].
  • API keys are scoped, hashed at rest and rotatable.

Data protection

  • TLS in transit; encryption at rest provided by the hosting platform [confirm].
  • Provider credentials stored in a secret manager / encrypted store; masked in logs.
  • Files (imports, recordings, reports) in private object storage, served through short-lived authorized links.
  • Recording and transcript access is permission-checked and audited.

Application security

  • Input validation on all APIs; sanitization of rich text and collected HTML evidence.
  • Protection against server-side request forgery on URL fetches.
  • Webhooks verified using each provider's supported method; replay protection and deduplication.
  • Public forms and tracking endpoints are origin-bound and rate-limited.

Operations

  • Audit logs for sensitive actions; support access requires permission and a recorded reason, and shows a visible banner.
  • Backups with a documented retention period; restore drills performed [frequency].
  • Dependency scanning in CI.

Reporting a vulnerability

Email [security@domain] with details. Please don't access other customers' data or degrade the service while testing. [Disclosure policy — to be defined.]