Trust center · updated 2026-07-27

Controls a buyer can verify before data moves.

Security architecture

Every stateful query is scoped to an organization. Retained source objects use AES-256-GCM with organization-bound authenticated context. Sessions, API keys, and SCIM tokens are one-way hashed. Contract versions and obligation events are immutable at the database layer.

Enterprise identity

The inherited factory supports OIDC Authorization Code flow with PKCE, signed identity-token validation, domain restriction, encrypted client secrets, and SCIM user provisioning. Owner deactivation is blocked.

Evidence and audit

Source citations persist through execution-state changes. Organization audit events and immutable obligation history can be exported for review.

Infrastructure

The VPS container runs non-root behind TLS with a read-only filesystem, dropped capabilities, health checks, resource limits, and encrypted off-box backup support. The public marketing build does not retain contract evidence.

Procurement documents

Data processing addendum · Security architecture · Privacy notice · Service terms

Assurance status

Reloren does not claim SOC 2, ISO 27001, HIPAA, PCI, or other certification without current independent evidence.