
Security & data handling
Last updated 4 September 2026
Relayworks AI does not use client data to train models. We work on commercial API tiers with training disabled, or on self-hosted open-weight models inside your own infrastructure where policy requires it. Access is least-privilege, credentials stay in your control where possible, and everything below is written into our contracts.
Your data is not training data
We use enterprise and commercial API tiers where the provider contractually excludes inputs and outputs from model training. Where your policy or regulator requires it, we deploy open-weight models on infrastructure you control, so data never leaves your boundary at all. Which applies to your engagement is agreed in writing before any data is shared.
Access and credentials
- Least-privilege access, scoped to the specific systems a project requires
- Credentials held in your secret manager wherever your infrastructure supports it
- Access provisioned at project start and revoked at project end, on a documented checklist
- Named individuals only — no shared accounts
- Multi-factor authentication required on all accounts touching client systems
Data residency
For Indian clients we default to Indian regions for data storage and processing where the underlying providers support it. For clients with specific residency requirements — including regulated healthcare and financial services — we scope the deployment to meet them, and we tell you plainly where any component cannot.
Personal data
We design to the principle that a system should hold the minimum personal data required to do its job. In practice: PII redaction before it reaches a model wherever the task allows, field-level restriction rather than whole-record access, and retention windows agreed with you rather than defaulted.
Where we act as a data processor under the Digital Personal Data Protection Act 2023, we sign a data processing agreement setting out purpose, retention, subprocessors and deletion.
Subprocessors
Any third party that would process your data — model providers, cloud infrastructure, monitoring tooling — is disclosed before the engagement starts and listed in the agreement. We do not add a subprocessor mid-engagement without telling you.
In the systems we build
- Guardrails on input and output, including PII scanning where relevant
- Confirm-before-commit on any irreversible action
- Audit trails — every automated action logged with its inputs and reasoning
- Human escalation paths for uncertain or out-of-scope cases
- Traceability, so any output can be reproduced and explained after the fact
What we do not claim
We are a small firm and we will not overstate our posture. We do not currently hold SOC 2 or ISO 27001 certification. If your procurement requires either, tell us early — we will either meet the underlying controls and evidence them, or tell you we are not the right fit. We would rather lose the work than misrepresent it.
Reporting a concern
If you believe you have found a security issue in something we operate, email contact@relayworks.in with the details. We acknowledge within one working day.