Keeping your Relay account secure works in two directions: Relay runs encryption, monitoring, and fraud detection behind the scenes, and you add strong passwords, two-factor authentication, and biometric login.
What can I do to keep my Relay account secure?
Six actions cover most account safety:
Use a unique, strong password. Never reuse the password from another site, especially another banking app. A password manager helps you keep unique passwords for every site.
Turn on two-factor authentication (2FA). 2FA is required on every Relay account. If you have not logged in since 2FA was enforced, you will be prompted to enable it on your next login.
Set up biometric authentication. Face ID or fingerprint ID adds a fast, secure way to log in from your mobile device.
Review transactions and account activity regularly. Watch for unfamiliar debit card creation, transactions, or logins. If something looks off, reset your password and contact the Customer Experience team.
Turn on email notifications for account activity. Get alerted whenever a payment is sent from your account.
Review your active sessions. Look for logins from unfamiliar devices or locations. If you spot one, reset your password and contact the Customer Experience team right away.
How to spot a phishing attempt
Phishing is when someone impersonates Relay to try to steal your login. Four rules make it easy to catch:
Relay will never ask for your phone number, password, or 2FA code over social media, text message, or email.
Relay's only login URL is https://app.relayfi.com/login.
Relay's official social handles are @relayfinancial on Instagram, X, LinkedIn, YouTube, TikTok, and Facebook. Any other Relay-branded account on these platforms is unauthorized.
Relay only sends email from @relayfi.com and @bankwithrelay.com domains.
How does Relay protect my account?
Relay's Security team runs four layers of protection behind the scenes:
Encryption. All data-at-rest is protected with AES-256-GCM encryption. All data-in-transit is protected with TLS 1.2 or higher, using Forward Secrecy.
24/7 infrastructure monitoring. Relay logs every access point through CloudWatch and CloudTrail. The Security team is alerted to unusual behaviour immediately and follows an established response procedure.
Employee security controls. Every Relay employee passes a background check and completes security training. Internal system access runs through zero-trust tunnels with full activity logging. Least-privilege principles, mobile device management, virus protection, and disk encryption are enforced across the company.
Regular penetration testing. Relay's Security team runs audits to find vulnerabilities before attackers do. A separate vulnerability disclosure program run through HackerOne adds continuous outside review.
How does Relay respond to fraud?
Three systems work together to catch fraudulent activity and limit damage:
Automated transaction monitoring. Relay's systems lock accounts and notify the account holder when a transaction falls outside normal spending patterns.
FDIC insurance up to $3M via Thread Bank. Customer deposits are eligible for pass-through FDIC insurance up to $3,000,000 when Thread Bank places them at program banks through its sweep program. FDIC insurance available up to $3M for funds deposited via Thread Bank; Member FDIC. Pass-through insurance coverage is subject to conditions.
Freeze or terminate a card from the app. If your Relay Visa® Debit Card is lost, stolen, or you suspect it has been compromised, you can freeze or terminate it from the Cards section of the Relay app.
The Relay Visa® Debit Card is issued by Thread Bank, Member FDIC, pursuant to a license from Visa U.S.A. Inc.
When does Relay require SMS verification?
Relay requires SMS verification any time you change your phone number or update login information on your account. A one-time code is sent to your previous mobile device as an added layer of identity verification.
For security reasons, Relay cannot make changes to your login information (including your mobile phone number) over email. If you need to update your phone number or other login details, contact the Customer Experience team so we can verify your identity and help you access your account.
How do I report a security vulnerability?
Relay runs an invite-only vulnerability disclosure program through HackerOne that pays security researchers for safely disclosing potential vulnerabilities in non-production environments. To request an invite, email security@relayfi.com.
Related articles
Talk to our Customer Experience team
If this article did not fully answer your question, our Customer Experience team is here to help.