Security

Scope the workflow. Verify the controls. Keep people in charge.

Security review belongs before carrier access. This page explains Relay's public control model and the questions an agency should verify against current documentation before production use.

Carrier compliance

How we work with carrier portals.

Security controls and carrier access rules both matter. No vendor can promise that a carrier will never challenge an automated session, so workflow fit includes the agency's applicable carrier terms and policies.

Human-in-the-loop by default

The agency reviews the submission and defines approval points before a configured run. Results and source evidence return to people for review; Relay does not make coverage or binding decisions.

Your credentials, your agency

Carrier access is agency-specific and configured only after fit and security review. Credential handling, administrative access, logging, storage, and revocation must be confirmed in the current security documentation before production use.

Rate-limited and respectful

Controls should be configured for the specific carrier workflow rather than assuming one traffic pattern fits every portal. The agency remains responsible for applicable carrier terms and access policies.

Monitored and held when needed

Configured early-access workflows are monitored for portal changes. When a change affects the workflow, Relay stops or flags the affected work until the path has been reviewed again.

Access due diligence

What to verify before sharing credentials.

Workflow-scoped access

Carrier access is discussed only for a workflow that has passed fit review. Scope is defined by carrier, line, state, authentication, and portal path before a run is enabled.

No credentials in the waitlist

Do not send passwords or client records through the marketing-site waitlist. Credential handling belongs in the controlled setup process for an invited agency.

Current documentation first

Before enabling portal access, ask for the current security overview, subprocessors, retention terms, incident process, and the controls that apply to your configuration.

MFA handling

How we handle multi-factor authentication.

Carrier MFA and session rules vary. Relay does not claim to bypass those controls. Fit review identifies the authentication path, the action required from your team, and whether the workflow can be supported before access is enabled.

Client data handling

How we handle your client data.

Collect only what the workflow needs

A bounded workflow should use only the source documents and fields required for that job. Broader access should require a separate decision by the agency.

Keep sources attached

Prepared fields and results should retain source evidence so a person can verify the work instead of trusting an unexplained output.

Define retention in writing

Retention and deletion requirements depend on the service configuration and agreement. Confirm the current terms before sharing production client data.

Keep decisions human

Relay does not replace coverage judgment or agency obligations. People review evidence and make every coverage, binding, issue, payment, and client-communication decision.

Compliance

Standards and compliance.

Certification status

Do not treat this marketing page as a certification or audit report. Request Relay's current security documentation and certification status during due diligence.

Agency responsibility

Your agency remains responsible for carrier agreements, licensing, data-handling duties, and deciding whether a workflow is appropriate for the information involved.

Carrier-specific review

Portal access and acceptable use can vary by carrier. Early-access fit review must include the agency's applicable carrier terms and access policies.

Change control

When a portal change affects a configured path, the safer behavior is to hold or flag the work until the workflow has been reviewed again.

Document the response path

Ask who to contact, how incidents are evaluated, what notice terms apply, and how access can be revoked before the workflow enters production.

Due diligence

Questions to ask any vendor.

If you're evaluating any automation vendor, including us, ask these questions:

  1. 01Where are my credentials stored, and who can access them?
  2. 02Is my data encrypted at rest and in transit?
  3. 03What happens to my data if I cancel?
  4. 04How do you handle carrier portal MFA?
  5. 05Do you have a security incident response plan?
  6. 06Can you provide documentation of your security practices?

Need current security documentation?

Join the waitlist and note that security review is part of your fit decision.

No spam. Just useful early access updates.

FAQ

Security questions, answered straight.

Can Relay employees see my carrier passwords?+

Do not send carrier passwords through the public website or waitlist. Credential access, storage, administrative access, and revocation controls must be documented for the agency during controlled early-access setup before any portal workflow is enabled.

What happens if there's a security breach?+

Incident response and notice obligations should be reviewed in Relay's current security documentation and service terms before production access. The public page does not promise a universal notice window.

Do you sell or share my client data?+

Relay does not sell personal information. Information may be handled by service providers that operate the site or service, as described in the Privacy Policy and the applicable service terms.

How do you handle carrier portal changes?+

Configured early-access workflows are monitored. If a portal change affects the path, Relay holds or flags the work for review until the workflow is validated again.

What certifications do you have?+

Request the current security overview and certification status during due diligence. Relay does not claim a completed certification on this public page.

Can I get a copy of your security documentation?+

Yes. Contact us at hello@relayins.com and we'll share our security overview and practices documentation.

Will carriers block our agency for using Relay?+

No automation can guarantee a carrier will never challenge or lock a session. Relay validates each early-access workflow with the agency, and agencies remain responsible for their carrier agreements and access policies.

Does Relay scrape carrier portals?+

Relay's quoting direction is authenticated, configured portal work—not collecting public website data. Exact access mechanics and human approval points are reviewed for the agency before a workflow is enabled.

What happens if a carrier changes its portal UI?+

Configured early-access workflows are monitored for changes. If a change affects the workflow, Relay holds the work for review until the workflow is updated and validated again.

Get started

Join the Relay waitlist.

Join agencies helping shape Relay’s early access, starting with quoting.

See how Relay works