Blockchain systems are unforgiving: contracts are immutable and keys are final. Security engineering is built into our delivery process, not added at the end.
Every contract we deliver goes through a structured assurance process before deployment:
Signing keys are held in managed, hardware-backed storage with strict separation between development, staging and production. Key operations require explicit authorisation and are recorded in the audit log. Client keys never leave client-controlled environments without a written agreement.
Platform and infrastructure access is role-based, least-privilege and reviewed regularly. Administrative actions require multi-factor authentication; production deployments can require multi-person approval depending on the engagement.
We maintain SOC 2 Type II and ISO 27001 controls and can provide the relevant reports under NDA. Our GDPR documentation covers data processing, retention and data subject requests for engagements that handle personal data.
If you believe you have found a vulnerability in a RelayLink system or in code we delivered, contact security@relaylink.io. We acknowledge reports within 24 hours and aim to resolve confirmed issues promptly. Please do not test against production systems without written permission.
Security questions during procurement? We are happy to complete security questionnaires and join technical due-diligence calls. Write to security@relaylink.io.