Standby access for the people who'll need it.
Relay is an encrypted vault of your accounts, credentials, and instructions — with scoped, reversible access that opens only under rules you set. When you can't act, the right people can — and not a moment before.
Received an access link? Open it from your email to reach your plan.
See it actually run
Two minutes on live infrastructure: a verified emergency release, a recipient decrypt, an owner check-in that closes access again, and a strongly-consistent read from the second region.
How Relay works
A thin vault and a thick release engine. The hard part — being correct under pressure — is handled by the database, not by hope.
Build the vault
Import a password-manager export or add accounts, documents, and instructions. An importance engine ranks what matters in a crisis — and shows that your primary email is the key that unlocks most password resets. It only ever sees non-secret metadata.
Set the rules
Decide who gets which items, under which trigger — a missed check-in, a manual emergency, or a verified estate event — with N-of-M trusted verifiers and a grace window before anything opens.
Controlled release
A trigger advances a state machine — ARMED → PENDING → GRACE → RELEASED — where every transition is a strongly-consistent compare-and-set on Aurora DSQL. It can never double-release, even when owner, verifiers, and scheduler all act at once.
Reversible by default
Recover and check in, and emergency access closes again automatically. Estate handoffs are permanent. The default-safe state is always ARMED.
Dense and deliberate. Build the vault, see the risk graph, set the rules, and arm the triggers. MFA on every sign-in; nothing releases by accident.
Calm and guided. A recipient opens one scoped link and gets a prioritized, do-this-first plan — revealing only what they were granted, only once a release has actually happened.
Built on a correctness-first stack
Active-active across regions, strongly consistent. The invariant — no double-spend, no oversell, no reconciliation — is owned by the database.
Per-item AES-GCM-256 data key, wrapped by KMS. Plaintext never leaves your browser; the server only ever stores ciphertext.
Every security event is an append-only, per-owner SHA-256 chain — tamper-evident and verifiable in the browser.
Two emotionally-distinct modes — dense blue Owner mode, calm amber Access mode — on one strongly-consistent ledger.
Caring for an aging parent?
The call comes, and suddenly you need their bank, their insurance portal, the email that resets all of it — and you need that access to end when the crisis does.
See Relay for caregivers →Put a plan in place.
It stays ARMED until you decide otherwise.