Trust center · updated 2026-07-27
Controls a buyer can verify before data moves.
Security architecture
Every stateful query is scoped to an organization. Retained source objects use AES-256-GCM with organization-bound authenticated context. Sessions, API keys, and SCIM tokens are one-way hashed. Contract versions and obligation events are immutable at the database layer.
Enterprise identity
The inherited factory supports OIDC Authorization Code flow with PKCE, signed identity-token validation, domain restriction, encrypted client secrets, and SCIM user provisioning. Owner deactivation is blocked.
Evidence and audit
Source citations persist through execution-state changes. Organization audit events and immutable obligation history can be exported for review.
Infrastructure
The VPS container runs non-root behind TLS with a read-only filesystem, dropped capabilities, health checks, resource limits, and encrypted off-box backup support. The public marketing build does not retain contract evidence.
Procurement documents
Data processing addendum · Security architecture · Privacy notice · Service terms
Assurance status
Reloren does not claim SOC 2, ISO 27001, HIPAA, PCI, or other certification without current independent evidence.