Available now

SECURITY

Security architecture with testable boundaries

RLX Gate uses defense in depth and documents residual risk. Implemented controls do not by themselves constitute certification.

Last reviewed

RLX GATE SYSTEM MAP
Control plane
OPERATORSPolicies & routes
SIGNEDVerified revision
Data plane
CLIENTSApps & agents
RLX GATEIdentity & policy
ENVOYRoute traffic
ORIGINSBackend APIs

Envoy keeps serving the last verified revision if the management console is unavailable.

Implemented controls

Discoverable user-verifying passkeys, strict sessions, CSRF and origin enforcement, protected root administration, deny-by-default tenant permissions, active hierarchy checks, and database invariants protect management access.

Content and runtime integrity

Uploads are quarantined and scanned before promotion. Runtime candidates and passkey records are integrity-bound, audit records are hash chained, and production containers reduce privilege.

Known gaps

Passkey recovery, multiple authenticator management, identity federation, field encryption, WAF, xDS ACK/NACK, centralized security telemetry, and encrypted off-host backups require further work.

Frequently asked questions

Is production passwordless?

Yes. Production setup, account activation, and sign-in require WebAuthn passkeys with user verification. Password endpoints are development compatibility only.

NEXT STEP

Evaluate the product against your real constraints.

Talk to ReallexiRequest platform access