Security model

Built so Relay cannot read your bookmarks.

Relay syncs bookmarks through an end-to-end encrypted, zero-knowledge vault. Your recovery key and any passkey PRF output stay on the client, bookmark contents are encrypted before upload, and the backend stores only encrypted vault data plus limited operational metadata.

Security receipt

Recovery key sentNo
Readable bookmarks on Relay serversNo
PermissionsBookmarks + storage + alarms
Review statusPlanned
End-to-end encrypted Zero-knowledge vault No analytics SDK Independent review planned
Data boundary

What Relay can and cannot see

Relay can store encrypted vault data

The server needs the encrypted blob, a derived vault lookup key, browser-limit metadata, rate-limit metadata, and plan state to operate sync.

Relay cannot read bookmark contents

Readable bookmark titles, URLs, folders, and profiles are encrypted in the browser before upload. The recovery key is not sent to Relay.

Relay can enforce ownership

Sensitive actions require a local ownership token recovered only after a browser decrypts the vault with the Recovery Kit password or, on compatible Chromium builds, a passkey.

Relay knows the chosen username

Relay intentionally stores the username, stable account and Support IDs, coarse authenticated activity, and sharing relationships for support, abuse controls, and product operation. It still cannot read the encrypted bookmark vault.

Relay cannot recreate your Recovery Kit

Recovery would require Relay to hold a decryption path. Relay intentionally does not.

Shared capsules use separate keys

Each shared collection is encrypted locally with a fresh random key kept in the URL fragment. Relay stores ciphertext and limited expiry, import, and revocation metadata, but the fragment key is not sent to the server.

Trusted sharing

Recipient keys keep live shares private

Each Relay account creates a P-256 sharing keypair. The public key supports contact sharing; the private key remains inside the encrypted vault. Live profile keys are wrapped for a specific accepted recipient, so the server can deliver and update encrypted shares without holding the key needed to read them.

Extension surface

Extension permissions

Relay's Chromium and Firefox clients request only the permissions needed for native bookmark sync and local bookmark tools. The optional passkey permission applies only to compatible Chromium builds:

Optional Chromium passkeys

Passkeys can approve a compatible Chromium browser; they do not replace vault encryption

On compatible Chromium builds, Relay stores the passkey public key, attached username, limited credential metadata, and a credential-bound encrypted recovery-key envelope. WebAuthn PRF output opens that envelope only on the client and is never sent to Relay. Compatible passkey providers may synchronize the credential across browsers and devices. Biometric data and device PINs stay with the operating system or passkey provider. Firefox uses the Recovery Kit password in its first release.

Local controls

Health, Tidy, and Undo stay browser-side

Library health checks, canonical URL-copy detection, local bookmark organization, Undo snapshots, and action result messages are computed from this browser's bookmark tree and local storage. They do not require Relay to read plaintext bookmarks on the server.

Verification

Independent verification roadmap

Relay is preparing for an independent browser-extension security review. We will publish only completed review summaries, not future-tense certification claims. The planned review scope is:

Current status: no third-party certification has been claimed yet. The Chrome Web Store is the live install path; the separate Microsoft Edge package is in Partner Center setup, and Firefox Desktop is awaiting Mozilla review and signing. Independent audit evidence will be added only after completion.
Disclosure

Report a security issue

Please use the support page for a coordinated reporting path. Do not send recovery keys, full bookmark exports, sensitive URLs, or exploit playbooks in an initial report.

Contact Relay support

Open the Relay Trust Center