$ curl -fsSL railcall.ai/install.sh | bash
Governance for AI action

The drafting surface cannot approve itself.

Every AI action runs through a human approval gate it cannot forge, leaves an Ed25519-signed receipt, and runs locally on 127.0.0.1 with your model keys. Governed by construction — and cheap because we’re not standing between you and your provider.

curl -fsSL https://railcall.ai/install.sh | bash
100% on 127.0.0.1 · $0 per executionBYOK · 0% AI markupSOC 2 Type II — audit in progress
Cut the platform tax.
BYOK · runs on 127.0.0.1 · zero per-execution markup · zero cloud compute to pay for →
100% HIPAA compliant.
Every §164.312 safeguard mapped · PHI stays on 127.0.0.1 · independent audit in progress →
Ed25519 receiptsBYOK · your keys, your bill
The AirlockSigned

AI proposes

wants to act

Stage

dry-run · 0 writes

Policy

rules gate it

Sign

Ed25519

Approve

human clicks

Receipt

signed · verified

railcall studio · receipt · 127.0.0.1
{
  "receipt_id": "rc_9f4c2e…",
  "flow": "client_sync",
  "actor": "sami@localhost",
  "airlock_status": "SECURE",
  "sockets": 0,
  "integrity_root": "sha256:c4f1…",
  "approver": "human · signed",
  "signature": "ed25519:…",
  "verified_offline": true
}
Built for regulated workIndependent audit — in progress

100% HIPAA compliant. Not paperwork — evidence.

Every HIPAA §164.312 technical safeguard is mapped, implemented, and provable in the product — not filed away in a policy binder. Protected health information never has to leave your infrastructure: the data plane is loopback, PHI is read, transformed, and governed at 127.0.0.1, and RailCall itself never receives it. That design is why we can be direct: the only unfinished piece is the letter from the auditor, and that audit is actively in progress. Everything underneath — access control, integrity, transmission, audit trail — is live today and you can point at it.

§164.312(a)

Access control

BYOK keys in a 0600 vault, resolved only on-box; every consequential action needs a terminal-only keypair approval the browser never sees.

§164.312(b)

Audit controls

Every action emits an Ed25519-signed, hash-chained receipt. Tamper any past entry and the chain breaks — evidence, not a log you have to trust.

§164.312(c)

Integrity

The approved bytes provably equal the fired bytes. Drift, a stale plan, or a bad signature fail closed — nothing executes.

§164.312(e)

Transmission

The highest-risk transfer — PHI leaving your network — simply doesn't happen. What reaches a model is your choice, under your own BAA.

Straight scope: RailCall is 100% compliant with the HIPAA §164.312 technical safeguards — access control, audit controls, integrity, transmission security — with every safeguard mapped to a specific product control you can point at. Adopting RailCall removes surface area instead of adding paperwork, and the independent audit in flight makes it a letter, not just an assertion. Compliance is provable, not just asserted.
The missing layer in AI

SaaS sold seats. AI sells labor.The wall in between is what RailCall solves.

AI agents deliver outcomes, not tools — the pricing unit is the action completed, not the seat that opened the app. But cloud agents can't scale into the enterprise because two things break immediately.

Deal-breaker 1
CISO risk
Enterprise security refuses to let cloud agents stream proprietary codebases, customer PII, and internal data into third-party LLM providers. Every AI-touch is a new subprocessor to review, a new data-flow diagram, a new DPA. Legal blocks the pilot before ops can start.
Deal-breaker 2
Margin collapse
Routing high-volume agent execution through centralized cloud models generates unsustainable API bills. A workflow that costs $0.20 per agent call becomes $60,000/month when 10,000 seats invoke it 30 times a day. The SaaS margin math stops working.
RailCall — the runtime that sits beneath Claude / Cursor / Codex

Local execution + cryptographic receipts. Not a wrapper, not a gateway — the layer that makes governed AI labor actually deployable past a CISO review.

Zero-COGS local compute
Execution runs on the customer's own hardware — 127.0.0.1, non-custodial. Every LLM call is a BYOK provider key the customer configured; RailCall never proxies that traffic. Zero cloud-model inference costs to us means we can price per seat, not per token.
Shipping · station-v0.27
Deterministic airlocks
Every workflow runs dry-run by default. External writes — DB updates, API triggers, deploys — are gated by a cryptographic approval token the agent cannot generate. Human sign-off is mandatory and provable, not aspirational.
Live · every module ships this
Ed25519 signed receipts
Every agent action, dry-run, and rollback emits an Ed25519-signed receipt hash-chained to the previous one (Haber-Stornetta 1991 lineage). Verifiable offline forever. The evidence artifacts your auditor asks for — SOC 2 CC6/CC7, HIPAA §164.312(b), ISO 27001 A.12.4 all cite 'signed, tamper-evident logs'. 100% HIPAA compliant, receipts you can hand to an auditor unchanged.
Status · Phase 2 shipping
Workflow Marketplace: live. Module Marketplace with Local DRM + recurring subscriptions: live. First subscription module (Salesforce CRM · $199/mo) is listed — buy flow is a real Stripe live-mode subscription pointed at a real license-mint service. No external buyers yet; we're seeding.
Break the cloud tax

Same task. Two bills.

One dev workflow, priced two ways. Cloud AI meters every step at frontier rates — reading files, running tests, re-sending your whole repo as context, retrying failed runs. RailCall runs all of that on the machine you already own, at 127.0.0.1, for $0. You pay a frontier model for exactly one thing: the reasoning.

Reasoning — you pay (identical both sides)Cloud compute tax — metered mechanical work$0 · runs local on 127.0.0.1
Cloud AI
everything metered
$168
$160
$140
$52
$520
/ mo · ALL BILLED
RailCall
local-first
$52
$0 · local
$52
/ mo · REASONING ONLY
$0
Your compute bill is zero. You pay $52 for reasoning either way — the cloud just charges you $468 more for work your own machine does for free. That's the monopoly cloud tax, gone — up to 90% less.
Illustrative one-workflow month. Actual savings vary by workload and how much runs locally.
Architecture · live

Almost nothing leaves your machine.

Everything inside the box runs on loopback. The only two paths off the machine are reasoning tokens to a model you chose, and — on the paid tier — a signed API-key handshake that pulls a library primitive. No run-count ping, no workflow data. Your keys, source, and records never cross the line.

data-flow · what runs where● live
YOUR MACHINE · loopback 127.0.0.1
AI agent
Claude / Codex, your key
Local compute
file ops · builds · tests
BYOK vault
keys at 127.0.0.1
0600 · never transmitted
Dry-run airlock
signed preview · 0 writes
Policy gates
approval · freeze · floors
Signed receipts
Ed25519 · hash-chained
0600 · never transmitted
⛔ Never crosses this line: your keys · your source · your customer records
Frontier model
Your key, your bill. Gets the reasoning step only.
↗ reasoning tokens
RailCall registry
Paid tier only — signed API-key handshake to pull a library primitive. No run data.
↗ api-key · pull primitive
stays on your machineleaves the machine (logged, minimal)
Governance that holds at any scale

One workflow. 1,333 governed nodes. One signed root.

A deterministic corpus of governed workflows was run through the real engine — every node policy-gated, the entire blast radius folded into one plan, and that plan Ed25519-signed and offline-verified. The declared ceiling is 5,000 nodes; the proof reaches 1,333 in a single workflow.

Why the number matters: a real-world enterprise workflow routinely fans out past 500 governed steps (invoice batch, tenant sync, incident triage). 1,333 in one plan means we can hold your whole flow — not just a demo excerpt — under one signed receipt.

2,772
governed workflows
471,772
governed nodes
1,333
deepest single workflow
100%
planned · signed · verified
index_rootsha256:bcd430caf9bd3aa64e5b410b121f7b7cd86b2ac028b0f279fc2667cf7160057a● real · sealed on disk
Scope, stated plainly: the 1→1,333-node scale is the plan + policy-gate + Ed25519-sign + offline-verify pass (0 failures). Full saga execution + rollback is proven to ~100 nodes today.
Why it's cheaper

Three tiers. Frontier tokens only for the last one.

The biggest saving isn't a local LLM — it's the deterministic layer digesting a 200KB codebase down to a few KB of exact context before a paid model ever sees it. That saving is free, exact, and the hardest thing for anyone to copy.

Tier 1

Deterministic

free · 0 tokens · exact

Find symbols, read files, map dependencies and tests — AST + index work, not even a model. It can't hallucinate, and it beats every alternative because it's free.

  • Symbol & reference search
  • Dependency & call graphs
  • Context packed to a few KB
live (partial)
Tier 2

Local model

cheap · on your hardware

The fuzzy calls — "which of these is the auth function," "summarize this file in two lines" — handled by a small local model so the frontier model never has to.

  • Ambiguous-match triage
  • File / diff summarization
  • Runs on your box, no cloud
◇ roadmap
Tier 3

Frontier model

paid · rare · your key

The actual plan and the actual code, on your BYOK key. It receives a small pre-digested bundle instead of a raw folder dump — so you pay frontier rates only for real reasoning.

  • The plan & the diff it writes
  • Pre-digested context in
  • Signed receipt out
live

Token-metered agent framework

10 workflows · one month · illustrative
Generate 10 · ~3M tok ea$300
Drift → rebuild · ~3$90
Run 1,000× · re-reasons each call$250
Total~$640 / mo

RailCall — local free · protocol metered

compose once · run locally · illustrative
Compose 10 from library · local$0.00
Run 1,000× · local, unmetered$0.00
Reasoning · your BYOK key~$30
Total~$30 / mo + protocol

Illustrative model, not a measured benchmark. Actual savings vary by workload, local-execution share, and rework prevented. We publish the calculator, not just the headline.

See it in action · live

Prompt to signed receipt — on 127.0.0.1.

Watch the Studio execute a real governed workflow, from a natural-language prompt to a cryptographically signed receipt, entirely on your machine. Your data. Your proof.

RailCall Studio demo
RailCall Studio Demo — Governed · Verifiable · Offline▶ runs on 127.0.0.1
The Studio · Ledger & Approvals

Your compliance surface, drawn live.

Receipts stop being raw JSON and become a picture a CTO or auditor reads at a glance: an unbroken hash-chain, live workflow approvals with their full blast radius, a measured airlock, and a running tally of what the local layer saved.

cryptographic ledger · hash-chain◇ roadmap UI
RECEIPT N−1client_syncsockets 0 · humanroot c4f1…9a2
RECEIPT Nappend_rowsockets 0 · humanprev c4f1…9a2root 7be0…41d
RECEIPT N+1charge_intentsockets 1 · approvedprev 7be0…41droot 1af8…c37
TAMPER?edited off-chainprev ≠ 1af8…c37chain breaks red

Airlock radar

lsof socket sweep · per run
0external sockets
● SECURE · isolation measured

Context savings

deterministic tier 1 · modeled
$1,240
◇ modeled from context-flattening, not billed
● verified link✕ broken / tamperedhover a block → actor · time · airlock · proof
pending workflow · approve & runlive
lead_to_cash
hubspot → linear → slack → stripe!retry → webhook
nodes5
systems4
irreversiblestripe · $1,250
egress2 domains
sockets (dry)0
signatureed25519 ✓
⚠ requires human sign-off — irreversible action in blast radius
APPROVE CODE is read from the launching terminal — the browser never sees it, so this surface can't approve itself.
Set the rules · live

When you build a workflow, you choose the permissions.

Every step declares an action class. You decide what runs itself and what waits for you — but the hard floors can't be widened: anything irreversible or that moves money always requires a human, no matter what the policy says.

compose · lead_to_cash · choose per-step policy● your choice
fetch lead
read · reversible
Auto-approveRequire humanBlock
format row
transform · pure, no effect
Auto-approveRequire humanBlock
charge $1,250🔒 hard floor
stripe · irreversible · moves money
Auto-approveRequire humanBlock
post to Slack
external send · reversible-ish
Auto-approveRequire humanBlock
Floors you can't widen: irreversible actions and money movement are locked to Require human — auto-approve is greyed out on step ③ and no rule can turn it on.

The policy is itself a governed write. An agent can never loosen its own leash. A standing rule — "auto-approve reversible updates under a limit, always stop for anything irreversible or money" — stages, gets approved with the terminal APPROVE code, and lands as a signed receipt.

{ "policy_id": "pol_widen_01",
  "widens": "reversible.under_limit",
  "approver": "sami@localhost",
  "signature": "ed25519:…" }
v0.6.0 — governance HUD

RailCall for VS Code.
A sidecar to Copilot, Cursor, Claude Code — not a competitor.

Whatever AI you already use to write code, RailCall governs what it actually does. The extension surfaces the local airlock in-editor: a Pending Approvals tree you clear with one click, a live Receiptsfeed you can verify offline, and a status-bar chip showing pending count + today's receipts at a glance. No chat window, no third opinion on your suggestions — just the trust layer that catches every consequential action.

Pending Approvals in-editor
Staged actions from the local airlock queue in a tree. Approve with one click — the signed receipt names you as approver (approval_channel=vscode_hud).
Live signed receipts
Every governed action emits an Ed25519-signed receipt the instant it lands in receipts/capoff. Verify it offline, independent of RailCall's servers.
Blast-radius workflow approval
Multi-step MCP workflows show their whole blast radius — nodes, systems touched, irreversible actions, egress domains, spend — before you Approve & Run.
Statusbar at a glance
One line: pending-approval count when there's work to do, today's receipts + station version when the queue is clear. Warns on version drift.
Works next to any coding AI
Copilot, Cursor, Claude Code, Continue — RailCall doesn't touch your suggestions. It governs the action your AI would take, once you ask it to run.
100% local by default
The station daemon runs on 127.0.0.1. The extension reads receipts from your local FS. Nothing leaves your box unless a workflow you approve fires an external send.
Installv0.6.0 · MIT · ~30 KB
Step 1 · Install RailCall Studio
$ curl -fsSL https://railcall.ai/install.sh | bash
Step 2 · Install the extension
Download .vsix (v0.6.0)

In VS Code: Cmd+Shift+P Extensions: Install from VSIX… → select the downloaded file. Cmd+Shift+L opens the HUD.

Requires VS Code 1.80+ · Cursor and VSCodium compatible · sidecar to any coding AIFull setup guide →

Now shipping · Model Context Protocol (MCP) — drive RailCall from Claude Desktop, Cursor, and any MCP client; MCP-staged workflows surface right here in Pending Approvals with their full blast radius

Why it pays back

Governance that also saves money

RailCall pays for itself four ways. The governance is why buyers install it. The math is why finance signs off.

BYOK · no AI markup
Your OpenAI bill stays your OpenAI bill

Bring your own keys — RailCall takes zero cut of AI spend. Hosted-AI vendors typically add 30–100% markup on top of the same tokens. On a $1k/mo AI bill, that's $300–1000/mo back.

Compare us to any vendor that charges per-token or 'AI credits'.
Flat seat pricing
No per-execution fees. Ever.

$100/seat/month whether you run 10 workflows a day or 10,000. No bill shock at end of month, no burst charges on a busy week.

Predictable line item finance can budget once.
Airlock catches mistakes
One prevented incident pays for years

Every irreversible write goes through preview → approve → execute. A bad batch caught in dry-run costs nothing. Caught in production it costs refunds, apologies, engineering time, and a client meeting nobody wants.

The Airlock is what governance looks like at the wire.
Marketplace skips build cost
Install, don't build

Signed, vetted integrations for CRM, billing, support, DevOps — free or single-digit-dollars each. An in-house Zendesk or HubSpot connector runs $15k–40k in engineering time you don't have to spend.

12 publishers shipping · growing weekly.
Every number above comes from published pricing + observable competitor rates. Ask us for the math on any tile.
Who's building it

A founder who's done the hard exit — building the next one in the open.

RailCall is led by an operator who has already built and sold a company through real diligence, paired with an engineering team shipping the governed engine release by release.

PL
Founder & CEO

Patrick Linden

Founder of Atlantic Energy (scaled across 36 utilities). Operator who raised a $75M debt facility (Signature Bank / V3) and led the exit at Gainline Partners. Builds for teams where data integrity and compliance must be verifiable, not assumed.

SB
Co-founder & CTO

Sami Ben Chaalia

Senior full-stack + AI engineer — 'MVPs in Days'. Ships across the RailCall stack alongside the team: runtime, airlock, marketplace, Studio. Previously co-founder & CTO at Tynass IT, elected top-3 AI startup in Africa at Afric'up 2019 (Tunis) among 1,400 participants from 42 countries.

KB
CFO

Kyle Burke

Runs finance and the commercial model — pricing, unit economics, and the path from free-local adoption to enterprise revenue.

NC
COO

Nick Capozzo

Runs operations and go-to-market — the developer community, launches, and getting RailCall in front of the teams who need it.

$75M+
debt facility raised (Signature / V3)
36
utilities Atlantic Energy scaled across
Top 3
AI startup · Afric'up 2019 (Tunis)
2nd
venture, founder-led
Pricing

Free to run. We monetize the trust layer.

The whole local runtime is free — download it, run unlimited workflows, keep every credential on your machine. We make money on the layer around it: a marketplace with a 5% take-rate (creators keep 95%) and enterprise governance for teams whose CISO needs central policy, audit, and spend controls. Runtime is never metered on any tier, ever.

solo developer

Free

$0
solo · run locally · forever
  • The uncrippled local engine + Studio
  • Unlimited local runs — never metered
  • Signed Ed25519 receipt per action
  • Hash-chained tamper-evident audit trail
  • BYOK provider keys, 0600 vault
  • Nothing leaves 127.0.0.1
Install now
Most popularbuy for a team of 2+

Team

$100
per seat / month · min 2 seats · 14-day free trial
  • Everything in Free, for your whole team
  • Multi-seat + RBAC (5 roles: owner / admin / publisher / operator / viewer)
  • SSO — Okta, Azure AD, Google Workspace, any SAML/OIDC
  • SCIM directory sync — auto-add/remove on IdP events
  • Configurable receipt vault (local · S3 · NFS · custom)
  • Admin audit log for every mutation
  • Long-lived API keys for CI/CD publishing
Start free trial

Enterprise

Custom
BAA · DPA · SLA · dedicated support
  • Everything in Team
  • Signed BAA (HIPAA), DPA (GDPR)
  • Air-gap install path (offline tarball)
  • Contractual SLA + incident response commitment
  • Direct support channel + dedicated engineer
  • Custom vault driver + SCIM group→role mapping done for you
Talk to us
Compare tiers

What's in every tier

FeatureFreeTeamEnterprise
Runtime
Local Studio + engine (unmetered)
Ed25519-signed receipts (per action)
Hash-chained audit trail
Airlock — human approval on every write
BYOK provider keys (0600 vault)
Marketplace install (free listings)
Team & access
Seat minimum12Negotiated
Multi-seat + RBAC (5 roles)
SSO (Okta / Azure AD / Google / SAML / OIDC)
SCIM directory sync (auto add/remove)
Admin audit log (every mutation)
Long-lived API keys for CI/CD
Org-internal listings (private catalog)
Compliance
HIPAA §164.312 technical safeguardsEvery tier ships the same technical controls.
Signed BAA (HIPAA)
DPA (GDPR)
Configurable receipt vault (S3 / NFS / custom)
Air-gap install kit (offline tarball)
Data export (JSON + receipts)
Support & guarantees
Community Discord
Contractual SLA + incident response
Dedicated support engineer
Custom SCIM group→role mapping
Free trial14 daysBy arrangement
Selling modules? RailCall takes 5% on one-time workflow sales, 25% on subscription modules — same rate regardless of tier. Browse the marketplace →

The runtime is free, always.  ·  Every tier ships the same signed-receipts + airlock + local execution. Team + Enterprise buy team seats, admin surfaces, and enterprise compliance signals — not different capabilities.

The roadmap

Each phase sells a bigger unit of value— on the same local, provable rails.

Platform roadmap · workflows → modules → compute

Phase 01 · SHIPPINGLive

Workflow Marketplace

primitives · 5% take · displaces Zapier / n8n
Sell the workflow

Signed workflow primitives cleared on our rail. Live: publish + install pipe, creator payouts, reviews + ratings, live-mode Stripe subscriptions, Local DRM (per-install signed licenses).

Browse the marketplace
Phase 02 · SHIPPINGLive

Module Marketplace

vertical AI modules · recurring ARR · signed writes
Govern the AI writes into your CRM

Domain experts publish whole vertical AI modules — signed handler bundles that register as new airlock commands. Local DRM binds each subscription cryptographically to one install: recurring ARR on self-hosted software, cryptographically enforced. First module live: Salesforce CRM — 20 airlock commands, $199/month, every write signed. Governs what your AI does INTO Salesforce; doesn't try to replace it.

See Salesforce module ($199/mo)

Phases 2–3 are directional. Sequencing is the strategy: workflows seed the marketplace, modules turn it into recurring vertical-software revenue, the installed base becomes the compute network — all on the same local-first, receipt-backed rails shipping in Phase 1.

Marketplace · Live

Buy signed workflows. Sell yours.

Browse all

Every listing is Ed25519-signed and pinned in the receipt ledger. Install with one command. Creators keep 95% — RailCall takes a 5% platform fee and pays out on demand.

Loading catalogue…

Download RailCall Studio. Run your first governed flow in minutes.

Free forever for one — unlimited local runs. No card. Runs on your machine. You own the code — even after you cancel.

We are simply the protocol. Download and run the full local Studio — you own the UI, workflows, primitives, everything. Customize whatever you want.

or curl -fsSL https://railcall.ai/install.sh | bash

No fake green

If we can't prove it, we don't claim it.

  • ● liveFree local execution, signed receipts, offline verify, the four floors, dual-control, hash-chained journal. Red-teamed and holding — this is the moat.
  • ● liveDeterministic code intelligence — symbol search, dependency & call graphs, test mapping. Zero tokens, no hallucination.
  • ◇ roadmapTier-2 local-model routing and hosted library resolution. Architected, not yet shipped — shown as direction, not fact.
  • ◇ roadmapThe visual Ledger Monitor & savings counter. This screen is a design preview; savings shown are modeled, not billed.

UNKNOWN means unverified — not a pass. Safe by default: RailCall runs in dry-run / proof mode. No live send, charge, or settlement happens unless you approve it.