Data minimization
Do not send secrets or regulated production data during initial discovery. Evaluation datasets should be de-identified or synthetic where that still tests the relevant behavior. Reliova requests only the fields needed to reproduce and score the workload.
Credentials
API credentials should be scoped, stored server-side, rotated, and separated by environment and customer. Credentials are not requested through the public website form.
Serving-route review
Before production token access, Reliova documents the serving route, data region, transport security, retention behavior, subprocessors, model changes, incident escalation, and deletion process. If these facts cannot meet the customer’s requirement, the route should not be used.
Logging and retention
Website contact submissions are delivered to Reliova’s configured business mailbox and retained as needed to respond and maintain business records. API evaluation and production logging are defined for the selected service configuration. This website makes no blanket zero-retention claim.
Responsible disclosure
Report a suspected vulnerability to randy.qin@reliova.com. Include reproduction steps and avoid accessing or altering data that is not yours.
Customer responsibilities
Customers remain responsible for lawful data collection, user notices, access controls, output review, human oversight, and determining whether a workload is appropriate for the chosen model and jurisdiction.