Hermes RelayHermes RelayRequest a Pilot

Trust

Security

Effective: September 2026 · Sui-Generis LLC

Architecture & Data Handling

Hermes Relay is a zero-egress, on-premise tool. Customer data never leaves the customer's environment. We have no servers that touch customer PHI. There is nothing for us to hold, store, or be audited on.

Encryption

All attestation receipts are signed with Ed25519 keys. The vault uses AES-256-GCM encryption. TLS 1.2+ in transit.

Signing Key Integrity

Each deployment generates its own Ed25519 signing key pair. Keys are non-exportable from the deployment environment by design. Receipt signatures are verifiable without trusting our infrastructure.

Vulnerability Disclosure

Responsible disclosure contact: andrew@hermesrelay.dev. We aim to respond within 48 hours.

SOC 2

Not applicable. Because Hermes Relay is zero-egress and on-premise, we do not process, transmit, or store customer data on our infrastructure. SOC 2 is designed for cloud SaaS vendors who hold customer data — that is not our model.

Privacy Policy

See our Privacy Policy.