Relm API + MCP.

Explore
SecuritySecurity

A security pass across the app and public site

Sign-in links can only return you to a Relm page, live analysis progress no longer carries your session token in the address bar, public forms can challenge automated traffic, and the endpoints that move money or credentials are rate limited.

1.15.2

A hardening pass with no change to how you work. Recorded here because you should be able to see it.

  • Sign-in and workspace links only ever return you to a Relm page. Every return destination is checked before we follow it — and a legitimate one is no longer dropped, so you land back where you asked for instead of on a default page.
  • Live analysis progress uses a short-lived ticket. The connection that streams research progress no longer carries your session token in the address bar.
  • Public forms can challenge automated traffic. Newsletter sign-up and the enterprise contact form support a bot check.
  • Rate limits on the endpoints that matter most — the ones that move money or exchange credentials — and a stricter set of browser security headers on every response.

Security questions, or need our current documentation? Reach out through support.