Skip to content

Legal

Security

This page describes how Skytells approaches security for Relam. It is intended for customers, partners, and security reviewers.

Last updated: September 18, 2026

Security is foundational

Relam is built and operated by Skytells, Inc. Security is part of how we design, deploy, and run the product—not a separate checklist applied after launch. Our goal is to protect customer data, workspaces, and the integrity of the service through layered controls, governed operations, and accountable provider relationships.

This page describes our security approach at a high level. It does not disclose confidential architecture, implementation details, or operational playbooks that could increase risk if published.

Defense in depth

We use a defense-in-depth model: multiple complementary safeguards across people, process, and technology so that a failure in one layer does not by itself compromise the service. That includes secure engineering practices, controlled access, monitored operations, and contractual requirements for subprocessors that support the platform.

Secure development and operations

Security considerations are integrated into how we plan, build, and operate Relam. That includes requirements and design review for sensitive features, controlled change management, separation of duties where appropriate, and operational monitoring designed to detect abuse, anomalies, and service-impacting events.

We maintain internal standards for authentication, authorization, logging, vulnerability management, and incident handling. Details of those controls are not published here.

Identity, access, and governance

Access to customer environments and production systems is limited to personnel and subprocessors with a legitimate need, subject to authentication, authorization, and review appropriate to the role. Within the product, permissions, memory settings, connected tools, sharing, billing entitlements, and model routing are enforced on the server rather than relying on the client alone.

For more about how requests are governed, see our Privacy Policy and Subprocessors page.

Protecting customer data

We treat customer content, account information, and operational data as assets that require protection throughout their lifecycle in the service. That includes measures designed to safeguard data in transit and at rest, restrict access, and support deletion and retention in line with our policies and customer instructions where applicable.

We do not publish specific technical configurations, network diagrams, key-management procedures, or other implementation details on this page. Organizations with a written agreement may request additional security information through the channels described below.

Infrastructure and providers

Relam runs on governed infrastructure operated or contracted by Skytells. Skytells-native model processing uses private network infrastructure. Third-party model and cloud services are engaged through enterprise deployments with leading providers, as described in our legal and privacy documentation.

We assess subprocessors for the functions they perform and require contractual commitments appropriate to the services they provide. A list of provider categories is available on our Subprocessors page.

Incident response

We maintain procedures intended to identify, contain, investigate, and remediate security incidents affecting the service or customer data. Where an incident affects customer personal data processed on behalf of an organization, we will provide notifications consistent with our agreements and applicable law.

Shared responsibility

Security is a shared responsibility. You are responsible for safeguarding your credentials, configuring account and workspace permissions appropriately, reviewing connected tools and sharing settings, classifying the data you submit, and using the service in accordance with our Terms of Use and Acceptable Use Policy.

Authorization for assessment and research activities

Access to Relam and related Skytells systems is provided for authorized product use under our agreements and policies. Except where we have given prior written approval for a defined scope, customers, researchers, and other third parties are not authorized to conduct independent assessments of, or research against, the service, underlying infrastructure, connected environments, APIs, interfaces, authentication flows, administrative surfaces, or any Skytells-hosted property reachable through or in connection with the service.

Without limiting the foregoing, activities that require our advance written consent include any attempt to evaluate, measure, interfere with, or defeat the security, integrity, availability, confidentiality, or performance characteristics of the service or related systems. This encompasses automated or manual vulnerability identification, penetration or adversarial simulation exercises, red-team or purple-team engagements, fuzzing or fault injection, exploit validation or proof-of-concept development against live environments, network or service discovery, port or endpoint enumeration, authentication or authorization bypass attempts, credential or session manipulation, injection or parser-abuse testing, timing or side-channel analysis, cryptographic probing, traffic replay or manipulation, stress or load generation, denial-of-service or degradation testing, social-engineering or phishing exercises directed at Skytells personnel or systems, subcontracted testing performed on our behalf without our knowledge, and any other activity reasonably understood to constitute security research, assurance testing, or control validation.

Engaging in such activities without authorization may affect other customers, impair service stability, breach contractual obligations, and contravene applicable law. Skytells reserves the right to investigate suspected unauthorized activity, preserve relevant records, restrict or terminate access, notify affected parties or providers, and pursue contractual, civil, administrative, or criminal remedies to the fullest extent permitted.

If you become aware of a potential weakness or incident, you should contact us through the reporting channel below and provide sufficient information for triage. Unless we expressly agree otherwise in writing, you must not continue testing, broaden scope, disclose findings to third parties, publish advisories, or otherwise exploit the matter before we have had a reasonable opportunity to review, reproduce, and respond.

Report a security concern

To report a suspected security vulnerability or incident related to Relam, contact support@relam.ai with "Security" in the subject line. Include enough detail for us to reproduce and investigate the issue. Do not include live credentials, large volumes of personal data, or destructive proof of concept.

We review good-faith reports and may follow up for clarification. Organizations with enterprise agreements may have separate security contacts or addenda.