Relay
Owner sign in

Standby access for the people who'll need it.

Relay is an encrypted vault of your accounts, credentials, and instructions — with scoped, reversible access that opens only under rules you set. When you can't act, the right people can — and not a moment before.

Received an access link? Open it from your email to reach your plan.

ARMEDPENDINGGRACERELEASEDevery transition strongly consistent

See it actually run

Two minutes on live infrastructure: a verified emergency release, a recipient decrypt, an owner check-in that closes access again, and a strongly-consistent read from the second region.

How Relay works

A thin vault and a thick release engine. The hard part — being correct under pressure — is handled by the database, not by hope.

01

Build the vault

Import a password-manager export or add accounts, documents, and instructions. An importance engine ranks what matters in a crisis — and shows that your primary email is the key that unlocks most password resets. It only ever sees non-secret metadata.

02

Set the rules

Decide who gets which items, under which trigger — a missed check-in, a manual emergency, or a verified estate event — with N-of-M trusted verifiers and a grace window before anything opens.

03

Controlled release

A trigger advances a state machine — ARMED → PENDING → GRACE → RELEASED — where every transition is a strongly-consistent compare-and-set on Aurora DSQL. It can never double-release, even when owner, verifiers, and scheduler all act at once.

04

Reversible by default

Recover and check in, and emergency access closes again automatically. Estate handoffs are permanent. The default-safe state is always ARMED.

Owner mode

Dense and deliberate. Build the vault, see the risk graph, set the rules, and arm the triggers. MFA on every sign-in; nothing releases by accident.

Access mode

Calm and guided. A recipient opens one scoped link and gets a prioritized, do-this-first plan — revealing only what they were granted, only once a release has actually happened.

Built on a correctness-first stack

Amazon Aurora DSQL

Active-active across regions, strongly consistent. The invariant — no double-spend, no oversell, no reconciliation — is owned by the database.

AWS KMS envelope encryption

Per-item AES-GCM-256 data key, wrapped by KMS. Plaintext never leaves your browser; the server only ever stores ciphertext.

Hash-chained audit

Every security event is an append-only, per-owner SHA-256 chain — tamper-evident and verifiable in the browser.

Next.js on Vercel

Two emotionally-distinct modes — dense blue Owner mode, calm amber Access mode — on one strongly-consistent ledger.

For the ones who step in

Caring for an aging parent?

The call comes, and suddenly you need their bank, their insurance portal, the email that resets all of it — and you need that access to end when the crisis does.

See Relay for caregivers →

Put a plan in place.

It stays ARMED until you decide otherwise.