Security: where your CRM data lives - Relaticle      

  Security 

 How Relaticle protects your data 
==================================

 Where your records live, who can reach them, and what the AI sees. Relaticle is open source, so most of this page can be checked in the code.

 [ Read the privacy policy ](https://relaticle.com/privacy-policy) [ Report a vulnerability ](#report) 

- [  No training on your data Relaticle does not train AI models on your CRM data. ](#ai)
- [  Rela asks first The built-in assistant proposes each change and waits for you. ](#ai)
- [  Passkeys and two-factor Sign in with a passkey, or require an authenticator code. ](#account)
- [  Open source AGPL-3.0. Read the code, or run it on your own server. ](#data)

  Your account
------------

How you sign in, and what protects the account.

 Passkeys Sign in with a passkey instead of a password. Passwords are stored hashed, never in plain text. 

 Two-factor authentication Require an authenticator code on every sign-in that does not use a passkey. You save recovery codes when you turn it on. 

 Google and Microsoft sign-in Sign in with the Google or Microsoft account you already use for work. 

 Session control Sign out every other browser session from Settings, Security. 

Your workspace
--------------

Who can reach a record, and how you see what they did.

 One workspace per record Every record belongs to one workspace. Each request is checked against that workspace before it reads or writes. 

 Four roles Owner, Admin, Member and Viewer decide what each person can see and change. 

 A log of every change The activity log on a record shows each field change and who made it. 

What the AI sees
----------------

Three ways AI touches your records, and what leaves Relaticle in each.

 The built-in assistant A request to Rela, a voice message or an email summary sends the content needed to answer it to an AI provider: OpenAI or Anthropic. Rela proposes every change as a card and waits for your approval. 

 Assistants you connect Claude, ChatGPT and other MCP clients receive only what they request through the tools you authorized, inside the one workspace you picked. Their changes apply directly. Relaticle does not see or store the conversation in your assistant. 

 On your own server Self-host Relaticle with your own provider key, or with a local model through Ollama. With a local model, the assistant sends nothing to an outside AI provider. 

Email and calendar
------------------

What happens when you connect a Google account.

 Only the account you connect Relaticle reads mail and calendar events only from an account you connect, and never changes, labels or deletes messages in your mailbox. It sends email and answers invitations only when you do that from Relaticle. 

 Encrypted tokens Mailbox access tokens are encrypted at rest. Disconnecting deletes them. 

  [Read the privacy policy for sharing settings, deletion and the Google Limited Use commitment.](https://relaticle.com/privacy-policy)

API and connector access
------------------------

Every token is scoped, and you can cut any of them off.

 Scoped tokens A personal access token is stored hashed and carries only the permissions you give it. 

 Expiring connector access Connector access tokens expire after 30 days and refresh tokens after 90. 

 Instant revoke Revoke a token or a connector under Settings, Access Tokens. It stops working at once. 

Your data stays yours
---------------------

Export it, delete it, or take it to your own server.

 Export Download every record type as CSV or Excel, custom fields included. The REST API reads the same records. 

 Delete Ask for deletion at privacy@relaticle.com. An account scheduled for deletion is removed after a 30-day grace period. Records in shared workspaces remain. 

 Leave Relaticle is open source under AGPL-3.0. Move to your own server whenever you want. 

  Service providers
-----------------

 The companies that handle data for Relaticle Cloud, and what each one receives.

 Service providers for Relaticle Cloud
| Provider | What it does | What it receives |
|---|---|---|
| Hetzner | Hosts the application and its database, in Germany | Receives All workspace data |
| Laravel Forge | Manages the server and runs deploys | Receives Administrative access to the server |
| Mailcoach | Sends account, notification and product update email | Receives Recipient name, address, message content and usage tags |
| Postmark | Delivers that email for Mailcoach | Receives Recipient address and message content |
| Stripe | Takes payment for Cloud plans | Receives Billing details. Card numbers go to Stripe directly. |
| Sentry | Reports application errors | Receives Error reports without your account identity. A report can include data from the request that failed. |
| Fathom Analytics | Counts page views on the website and in the app | Receives Page, referrer and signup events, without cookies |
| OpenAI, Anthropic | Run the AI models behind the assistant, voice input and email summaries | Receives The content of that request |
| Cloudflare | Checks that a new account is created by a person | Receives Signals from your browser on the create-account step |
| Google, DuckDuckGo | Look up a company logo | Receives The company domain |
| Maxforms | Hosts the support and feedback forms | Receives What you type into the form |
| Oh Dear | Watches uptime and health checks | Receives No customer data |

 A self-hosted install uses only the logo lookup, unless its operator configures the others.

  Report a vulnerability
----------------------

 Email what you found and the steps to reproduce it. Please do not open a public issue. We aim to acknowledge reports within 48 hours.

 [ security@relaticle.com ](mailto:security@relaticle.com) [ security.txt ](https://relaticle.com/.well-known/security.txt) 

  Security questions, answered
----------------------------

   Does Relaticle train AI models on my data?    No. Relaticle does not train AI models on your CRM data, does not sell it, and does not use it for advertising. 

   Is Relaticle SOC 2 or ISO 27001 certified?    No. Relaticle holds neither certification today. The code is open source, so the controls on this page can be read rather than taken on trust. 

   Can I move my data out of Relaticle Cloud?    Yes. Export every record type as CSV or Excel, read your records through the REST API, or run the same code on your own server. 

   How do I report a security problem?    Email security@relaticle.com with what you found and the steps to reproduce it. We aim to acknowledge reports within 48 hours.
