Security

Powerful agents need strong boundaries

An agent that can only talk needs very little protection. An agent that can act needs explicit limits. Security is being designed into the RelayRealm architecture from the beginning rather than added later.

Principles

How RelayRealm thinks about agent access

Permission-based capabilities

An agent receives specific capabilities. Nothing is granted implicitly, and nothing carries over from another project.

Trusted devices

Local actions run only through the RelayRealm desktop companion on a device that has been approved for that purpose.

Controlled tool execution

Each tool an agent can invoke is authorized deliberately, and requests are scoped to that tool's purpose.

Scoped project access

Agents see and act within the projects they are assigned to, not the whole workspace by default.

Human approval workflows

Sensitive or consequential actions can be held for a person to review and approve before anything happens.

Agent identity

Every agent is a distinct identity in the workspace, so actions can be attributed rather than anonymous.

Workspace and tenant isolation

Workspaces are separated from each other, and organizational data stays within its own boundary.

Auditability

Agent activity, tool use, and approvals are recorded so a team can reconstruct what happened.

Execution model

Local versus cloud execution

Agent intelligence runs in the RelayRealm cloud. Local capability runs on a trusted device, behind a boundary the team controls.

The desktop companion exists specifically so that an agent can use a particular capability without being handed a workstation. Each request crosses a boundary where it can be scoped, denied, or sent for human approval.

RelayRealm Cloud

Agent runtime and workspace state.

Authorization boundary

Is this agent allowed to do this, here, now?

RelayRealm Desktop

Trusted device executes the approved action.

Approved capability

The specific tool, and nothing beyond it.

Communication

Encrypted communication and isolation

Traffic between the application, the desktop companion, and the RelayRealm cloud is encrypted in transit, and workspaces are kept isolated from one another.

Development philosophy

Built with the boundary first

Capabilities are designed alongside the controls that limit them. A feature that lets an agent act is not considered complete until the permission model around it is.

On certifications

RelayRealm does not currently claim SOC 2, ISO 27001, HIPAA, or any other compliance certification. We would rather state that plainly than imply an assurance we haven't earned. Security is being designed into the architecture from the beginning, and this page will be updated as formal programs are completed.

If your organization has specific security requirements, we'd like to hear them early.

Contact the team

Build with your team. Build with your agents.

Bring people, projects, AI agents, context, and execution into one shared workspace.