Available now

API SECURITY

API security controls that fail closed

Security claims are limited to controls with implementation and test evidence. RLX Gate is not presented as certified or immune from compromise.

Last reviewed

RLX GATE SYSTEM MAP
Control plane
OPERATORSPolicies & routes
SIGNEDVerified revision
Data plane
CLIENTSApps & agents
RLX GATEIdentity & policy
ENVOYRoute traffic
ORIGINSBackend APIs

Envoy keeps serving the last verified revision if the management console is unavailable.

Identity and authorization

Production administration uses user-verifying passkeys, strict same-origin sessions, CSRF tokens, deny-by-default permissions, and protected tenant context. Gateway routes can separately require hashed API keys or asymmetric JWT/OIDC identity through fail-closed external authorization.

Untrusted input boundaries

OpenAPI uploads enter random tenant quarantine paths, stream through ClamAV, fail closed on scanner errors, and promote only after validation. Upstream URLs reject private and reserved networks by default.

Residual risk

WAF enforcement, schema-level runtime validation, centralized security analytics, hardware attestation policy, encrypted fields, and gRPC xDS acknowledgement remain incomplete.

Frequently asked questions

Is RLX Gate compliant with a specific standard?

Implemented controls can support an assurance program, but no certification or independent audit is claimed.

NEXT STEP

Evaluate the product against your real constraints.

Talk to ReallexiRequest platform access