Security
RELATIVITYOS SECURITY OVERVIEW
Tensyr LLC · Last updated September 22, 2026
This Security Overview is incorporated into the RelativityOS Terms of Service and describes the safeguards Tensyr maintains. Capitalized terms have the meanings given there.
This document describes practices. It is not a certification, and except where it expressly states otherwise Tensyr makes no representation that it holds any third-party security certification.
Information security is a dynamic field in which laws, regulations and threats change continuously. Tensyr accordingly reserves the right to change its security controls at any time, in a manner that Tensyr believes does not materially reduce the protection applied to Customer Data.
1. Security program
Tensyr maintains a written information security program, reviewed on approximately an annual basis, designed to protect the security, confidentiality, integrity and availability of Customer Data, to protect against threats and hazards to it, and to protect against unauthorized access to or use of it.
Responsibility for information security management is assigned to senior personnel.
2. Risk assessment and testing
Tensyr performs, on approximately an annual basis, a risk assessment designed to identify reasonably foreseeable internal and external threats to Customer Data, to assess the sufficiency of the safeguards in place, and to implement safeguards addressing the threats identified.
Tensyr engages, on approximately an annual basis, an independent third party to conduct a penetration test of the infrastructure on which the Service operates, and maintains a process to evaluate and address high-risk findings.
Tensyr maintains a process designed to identify, evaluate and remediate vulnerabilities in the Service and in the third-party components it uses.
3. Personnel
Personnel with access to Customer Data are subject to written confidentiality obligations that survive the end of their engagement.
Tensyr conducts background screening, to the extent applicable law permits, on personnel granted administrative access to systems holding Customer Data.
Tensyr provides security awareness guidance to personnel on approximately an annual basis.
4. Access control
Access to systems holding Customer Data is granted on the principle of least privilege, only to personnel who require it to operate, secure or support the Service.
Each individual with access is uniquely identified. Tensyr maintains a process designed to promptly disable access for any person who no longer requires it.
Tensyr requires multi-factor authentication for remote access to the environments in which the Service operates and for all privileged accounts.
The Service supports multi-factor authentication for Customer's Users. Credentials are stored using one-way hashing; Tensyr does not store passwords in a form that can be reversed.
5. Encryption
Customer Data is encrypted in transit over public networks using TLS 1.2 or greater, and at rest using AES-256 or an equivalent industry-recognized algorithm.
In addition to encryption at rest generally, Tensyr applies field-level encryption using AES-256 or an equivalent industry-recognized algorithm to the categories of Customer Data most likely to be sensitive, including the contents of messages, notes, health-related information and government identification numbers.
Endpoints on which Customer Data may be stored or processed are subject to full-disk encryption.
6. Separation
Each Customer is provisioned a separate instance of the Service. Tensyr maintains controls designed to maintain logical separation, such that Customer Data within one Account is not accessible from another.
7. Logging
Tensyr maintains audit logs of authentication events, administrative actions and access to Customer Data, designed to support the detection of and response to security incidents and to determine, per Account, which records were affected by an incident.
Acceptance records for the Terms of Service and the Policies are maintained on an append-only basis and are excluded from routine data deletion.
8. Development and change management
Tensyr maintains secure development practices, a process for evaluating the security of externally developed components it incorporates, a change management process for the environments in which the Service operates, and controls designed to protect against malicious code.
9. Infrastructure
The Service operates on infrastructure provided by third-party hosting providers whose environments are subject to independent third-party security examinations. Tensyr does not operate its own data centers and does not store Customer Data on removable media.
Tensyr's statement of the controls maintained by its hosting providers describes the infrastructure layer only and is not a statement about the application layer of the Service.
10. Resilience
Customer Data is backed up on a recurring basis, and Tensyr maintains measures designed to protect against destruction, loss or damage due to environmental hazards or technological failure.
Tensyr does not commit under this Overview to any recovery time objective, recovery point objective, uptime percentage or service level.
11. Incident response
Tensyr maintains a written incident response plan specifying the actions to be taken where Tensyr suspects or detects that a party has gained material unauthorized access to Customer Data, covering detection, triage, containment, escalation, notification and remediation.
Where Tensyr determines that a security incident has affected Customer Data, Tensyr will notify Customer without undue delay, and will use commercially reasonable efforts to promptly furnish the information it holds regarding the circumstances and extent of the incident. Tensyr's notice obligation is suspended for so long as Tensyr is prohibited from giving notice by law or by a law enforcement or governmental authority. Where permitted, Tensyr will notify Customer before commencing any external notification concerning an incident affecting Customer's Account.
Customer acknowledges that it may have its own notification deadlines measured from its own knowledge, and that Tensyr's notice obligations do not extend them.
12. Subprocessors
Tensyr engages subprocessors to perform the following functions in providing the Service:
| Function | Customer Data processed |
|---|---|
| Hosting, storage and supporting infrastructure | Customer Data generally |
| Telephony and messaging | Communications content and metadata |
| Artificial intelligence processing | Content submitted to AI features |
| Payment processing | Billing contact and payment information |
The identity of each subprocessor is available to Customer on written request to legal@tensyr.com, subject to Customer's agreement to treat that information as Tensyr's Confidential Information. Tensyr may decline a request made by or on behalf of a person that develops, operates or markets a product or service competitive with the Service.
Tensyr will give at least thirty days' notice before engaging a subprocessor in a function not listed above. Customer may object in writing within thirty days, on reasonable grounds relating to the protection of Customer Data. Where the parties cannot resolve the objection, Customer's sole and exclusive remedy is to terminate the affected subscription and receive a refund of prepaid unused Fees.
Tensyr will engage a subprocessor only where that subprocessor implements and maintains security measures Tensyr believes are no less protective than those described in this Overview, and remains responsible for its subprocessors' performance of the obligations Tensyr owes Customer.
Tensyr does not authorize any subprocessor to use Customer Data to train artificial intelligence or machine learning models.
13. Retention and deletion
Customer Data is retained for the duration of the Subscription Term. On termination it is available for export for thirty days in accordance with Section 14.9 of the Terms of Service, after which it is deleted from active systems and from backups in accordance with the backup rotation then in effect.
Tensyr maintains procedures for the secure disposal of Customer Data in any format, consistent with prevailing industry practice for rendering data unrecoverable.
Where Customer configures a retention period for any category of Customer Data, Customer is responsible for selecting one that meets its own obligations.
14. Customer responsibilities
The security of the Service depends on how Customer configures and uses it. Customer is responsible for:
- enabling multi-factor authentication for every User;
- provisioning and deprovisioning Users promptly, including on departure or change of role;
- granting administrative rights only to individuals who require them, and reviewing those grants periodically;
- configuring the Service to meet Customer's own obligations; and
- the security of the devices, networks and email accounts its Users use to reach the Service.
15. Diligence support
Annually, on Customer's reasonable written request, Tensyr will provide a written description of the security controls forming the basis of its security program, and an opportunity to discuss them with a qualified member of Tensyr's technical personnel.
Tensyr will respond within a reasonable period to a security questionnaire submitted no more than once in any twelve-month period, and may respond by reference to this Overview and that description.
This Section does not grant Customer a right to audit or inspect the Service, to access Tensyr's facilities or systems, to access data relating to any other customer, or to conduct security or penetration testing against the Service.
16. Representation
Tensyr represents that it has implemented, and during the Subscription Term will maintain, the security program described in this Overview. Tensyr does not warrant that the Service will be free from unauthorized access, intrusion, compromise or loss. Section 11.2 of the Terms of Service governs all other warranties and Section 13 governs liability.
17. Updates and contact
Tensyr may update this Overview on notice, in accordance with Section 16.2 of the Terms of Service, provided that no update materially reduces Tensyr's security commitments during a Subscription Term. Prior versions remain available in the archive.
Security questions and vulnerability reports: legal@tensyr.com