Trust centre

Security & data protection

We are asking you to trust us with your clients’ transactions. This page says plainly what we do, and — just as importantly — what we haven’t done yet.

Protecting the data

Encryption
All traffic is served over HTTPS/TLS. Data is encrypted at rest by our hosting provider’s managed storage.
Hosting location
SalesRelay runs on managed cloud infrastructure in the EU/UK region. We will confirm the exact region in your Data Processing Agreement before you go live.
Access control
Role-based access. Every user belongs to an agency and a branch, and can only see transactions belonging to their organisation. Consumer and professional links are scoped to a single transaction.
Tenant isolation
Agency data is separated at the data layer. Isolation is covered by automated tests, not just policy.
Backups
Managed, encrypted backups with point-in-time recovery on production databases.

Proving what happened

Immutable audit trail
Every status change, message and automated decision is written to an append-only log with actor, timestamp and reason. It cannot be edited from the product interface.
Evidence on every status
No milestone is marked complete without a recorded source: who said it, when, and the original message. Contradictory information raises a conflict for human review instead of overwriting silently.
Exportable
Agencies can export their transactions, milestones, communications metadata and audit records.

How we use AI

What the AI does
The AI reads inbound messages and extracts structured facts — a milestone, a date, a blocker — with a confidence score. That is the limit of its authority.
What the AI does not do
It does not decide status, send unreviewed messages in sensitive categories, or invent information. A deterministic engine applies the facts and schedules actions.
Low confidence and conflicts
Anything below our confidence threshold, and any contradiction between parties, goes to a human exception queue rather than into the record.
Training
Client transaction data is not used to train third-party foundation models.

Legal and regulatory

UK GDPR
Built to UK GDPR principles: data minimisation, defined retention, subject access export, correction and deletion workflows.
ICO registration
Keelson Holdings Ltd is registered with the Information Commissioner’s Office, registration number 00015117984.
Data Processing Agreement
A DPA is available to every agency customer. For most transactions the agency is controller and SalesRelay is processor.
Our regulatory position
SalesRelay is transaction coordination software. It is not a solicitor, conveyancer, estate agent, or financial adviser, and it does not provide legal or financial advice.

What we haven’t done yet

SalesRelay is early. We would rather tell you that than imply a maturity we don’t have. We do not currently hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 or SOC 2, and we have not yet commissioned an external penetration test. Cyber Essentials is our next step, with the others to follow as our customer base requires them. If a certification is a hard requirement for your agency, tell us and we’ll be straight with you about timing.

Questions, or need our DPA? hello@salesrelay.uk

See how it handles a real transaction.

The demo shows the audit trail and evidence model on every milestone.