Trust
Security
Effective: September 2026 · Sui-Generis LLC
Architecture & Data Handling
Hermes Relay is a zero-egress, on-premise tool. Customer data never leaves the customer's environment. We have no servers that touch customer PHI. There is nothing for us to hold, store, or be audited on.
Encryption
All attestation receipts are signed with Ed25519 keys. The vault uses AES-256-GCM encryption. TLS 1.2+ in transit.
Signing Key Integrity
Each deployment generates its own Ed25519 signing key pair. Keys are non-exportable from the deployment environment by design. Receipt signatures are verifiable without trusting our infrastructure.
Vulnerability Disclosure
Responsible disclosure contact: andrew@hermesrelay.dev. We aim to respond within 48 hours.
SOC 2
Not applicable. Because Hermes Relay is zero-egress and on-premise, we do not process, transmit, or store customer data on our infrastructure. SOC 2 is designed for cloud SaaS vendors who hold customer data — that is not our model.
Privacy Policy
See our Privacy Policy.
