---
title: "Relays and hosts"
url: https://loot.build/docs/concepts/relays
group: "Concepts"
status: written
summary: "What a host stores, what it can read, and why those differ."
---

# Relays and hosts

> What a host stores, what it can read, and why those differ.

A **relay** stores and forwards content it cannot read — **restricted** content, and embargoed content before its reveal. Those keys never travel in a sync bundle, so the property is enforced at the wire level, not by policy. It _can_ read **internal** content, the default tier: those keys ride along so peers pulling from it get readable files (ADR 0011), so a relay should list who may read it: with `--allow` only listed keys can pull, and without one anyone who can reach it can. A _host is just a relay that never sleeps_. [The trust matrix](https://loot.build/trust) states what each reader sees, tier by tier.
