Relevant · relevant.com.tr
Legal
Security
Relevant handles evaluation data that often includes customer questions and support content. This page describes how we protect it: how data flows through the platform, how it is encrypted and isolated, how long it is kept, and what we do when something goes wrong.
Found a vulnerability? Write to security@relevant.com.tr.
Last updated:
Our approach#
Teams send Relevant their questions, answers and retrieved passages. That is often customer-support content, so we treat every workspace as if it contained personal data and design the service so a mistake in one place does not expose another.
- In transit
- TLS 1.2 or higher
- At rest
- AES-256 encryption
- Access
- Role-based, per workspace
- Processing
- In the region you choose
- Least privilege by defaultNew members start with the narrowest role that fits. People and services get only the access they need, and keys can be revoked at any time.
- Isolation before featuresEvery request is scoped to one workspace at the gateway, before any evaluation logic runs.
- You decide where data livesCustomer content is processed in the region you choose and kept only for the retention period of your plan.
- Evidence over assertionWe describe what the platform does, publish our subprocessors, and state plainly what each control covers instead of implying more.
Architecture and data flow#
Relevant is a multi-tenant web service. Your applications, CI jobs and uploads reach an ingest gateway over TLS. The gateway authenticates the caller, resolves the workspace and passes the request to evaluation workers that read and write encrypted storage. People reach results through the dashboard, where roles decide what they can see.
LLM judges are optional. When a workspace enables one, only the samples submitted for judging (question, retrieved context, answer and gold answer) are sent to the model provider listed on the subprocessors page. Where you connect your own model provider account, the request goes to that account under your agreement with the provider.
Encryption#
In transit
All connections to the website, dashboard and API use TLS 1.2 or higher with modern cipher suites, and the site is served over HTTPS only with HTTP Strict Transport Security. Traffic between internal services is encrypted as well.
At rest
Datasets, traces, evaluation results and backups are encrypted at rest with AES-256. Encryption keys are held in the hosting provider’s key management service, separate from the data they protect, and are rotated on a regular schedule.
Secrets and credentials
Relevant never stores your password in readable form. API keys carry the prefix rlv_, are shown once when you create them and are stored only as a hash. Integration tokens are encrypted and can be disconnected from settings at any time.
Tenant isolation and access control#
Each workspace is a separate tenant. Its datasets, runs, failures and reviews are stored with the workspace identifier and every read and write is checked against it. Within a workspace, access follows four roles:
- Owner
- Can do
- Everything an Admin can do, plus billing, workspace deletion and ownership transfer
- Admin
- Can do
- Members, API keys, integrations, retention and data-region settings
- Member
- Can do
- Create and run evaluations, import datasets, triage failures and review ground truth
- Viewer
- Can do
- Read-only access to runs, failures, comparisons and reports
Enterprise workspaces add single sign-on (SAML and OIDC), SCIM provisioning and audit logs that record administrative actions such as role changes, key creation and revocation, integration changes and exports. Relevant staff access to customer content is limited to what is needed for support and operations, requires approval, and is logged.
Retention, export and deletion#
You control how long customer content stays in Relevant. Each plan has a default retention period for runs, traces and review decisions; content is deleted automatically when it expires.
- Free
- Retention
- 7 days
- Notes
- Runs, traces and review decisions
- Pro
- Retention
- 30 days
- Notes
- Runs, traces and review decisions
- Team
- Retention
- 90 days
- Notes
- Extended retention add-on keeps data for 12 months
- Enterprise
- Retention
- Custom
- Notes
- Set per workspace in the order form
- Export. Owners and Admins can export datasets, results and reports as CSV at any time.
- Deletion. Datasets and runs can be deleted by Admins. When an Owner deletes a workspace, deletion is scheduled for 14 days later, and the Owner can cancel until then.
- Backups. Encrypted backups are overwritten on a fixed cycle that does not exceed 35 days, and deleted data is not restored except to recover the service.
Regional processing#
When you create a workspace you choose the region where its customer content is stored and processed. Relevant does not move that content to another region except where you instruct it, where a listed subprocessor operates elsewhere, or where the law requires it. The hosting provider and regions are listed on the subprocessors page: our primary hosting provider operates EU, UK and US data centers.
Enterprise plans add VPC and on-premises connectors so traces can stay inside your own network. Transfers that do cross borders rely on the mechanisms described in the data processing agreement.
Application and infrastructure security#
- Secure developmentChanges are peer reviewed, built in a pipeline and promoted through separate environments. Dependencies are monitored for known vulnerabilities.
- Secrets managementCredentials live in a managed secret store, never in source code, and are scoped to the service that needs them.
- Logging and monitoringAuthentication events, administrative actions and platform errors are logged centrally and monitored for abuse and anomalies.
- ResilienceData is backed up in encrypted form and recovery procedures are exercised so the service can be restored after a failure.
- Network boundariesWorkers and storage are not directly reachable from the internet. Only the gateway and web front end accept inbound traffic.
- TestingAutomated security checks run on every change, and the compliance table below describes our testing program.
Customer content is never used to train models, by Relevant or by its subprocessors, and is never shown to another customer.
Incident response#
Relevant keeps a documented incident response procedure. When we suspect an incident that could affect customer data we follow the same stages:
- Detect and triageMonitoring, reports from customers or researchers, and automated alerts open an incident. An incident lead assigns a severity and starts a timeline.
- Contain and investigateWe stop the activity, revoke affected credentials, preserve evidence and establish what data and which workspaces are involved.
- NotifyIf customer personal data is affected, we notify the workspace Owner without undue delay and within 48 hours of confirmation, with what we know and what we are doing. That leaves you time to meet your own 72-hour obligations under GDPR and other applicable data protection laws.
- Recover and reviewWe restore normal service, then publish a post-incident summary to affected customers describing the cause, impact and the changes we are making to prevent a recurrence.
Vulnerability disclosure#
We welcome reports from security researchers. If you believe you have found a vulnerability in the website, the dashboard or the API, write to security@relevant.com.tr. We acknowledge reports within two business days and keep you informed until the issue is resolved.
What to include
- A description of the issue, its location and the impact you believe it has.
- Steps, requests or a proof of concept that let us reproduce it.
- Your contact details and whether you would like to be credited.
Our commitments
- We will not pursue legal action against good-faith research that follows this policy.
- We will tell you when the issue is fixed and, if you wish, credit you.
- We handle your report as confidential until a fix is available.
What we ask of you
- Test only accounts and workspaces you own, and stop if you reach another customer’s data. Tell us what you saw.
- Do not run denial-of-service tests, social engineering, or physical attacks, and do not degrade the service for others.
- Give us reasonable time to fix the issue before sharing details publicly.
Reports that only describe missing best-practice headers, automated scanner output without demonstrated impact, or issues in third-party services are out of scope. We do not currently offer monetary rewards.
Compliance program#
This table describes our compliance program. We align our controls with the SOC 2 Trust Services Criteria and ISO/IEC 27001 practices; reports are available to Enterprise customers under NDA. We state what each control covers and nothing more.
- SOC 2 Trust Services Criteria
- Scope
- Security and availability controls for the website, product and supporting systems
- Status
- Controls aligned with the criteria. Reports are available to Enterprise customers under NDA.
- ISO/IEC 27001 practices
- Scope
- Information security management across the website, product and supporting systems
- Status
- Controls aligned with ISO/IEC 27001 practices. Documentation is available to Enterprise customers under NDA.
- Penetration testing
- Scope
- Application and infrastructure
- Status
- Application and infrastructure testing is part of our security program.
- GDPR and UK GDPR
- Scope
- Processor obligations under the data processing agreement
- Status
- Data processing agreement available · Read the DPA
- Other data protection laws
- Scope
- Controller and processor obligations in the other jurisdictions where we operate
- Status
- KVKK notice published · Read the notice
Service status#
Service availability and incident updates for the website, dashboard, API and evaluation workers are published in this section. When an incident affects customers, its entry records when it started, what is affected, the current state and a short resolution note.
Current status: all systems operational. The website, dashboard, API and evaluation workers are running normally, and no incidents have been reported in the last 90 days.
Enterprise customers with a support SLA also receive direct notice of incidents that affect their workspace through the contacts named in their order form.
Contact#
For security reports write to security@relevant.com.tr. For anything about personal data, use the privacy contact below.
- Legal entity
- Relevant
- Privacy and data protection
- privacy@relevant.com.tr
- Legal notices
- legal@relevant.com.tr
- Security contact
- security@relevant.com.tr