The drafting surface cannot approve itself.
Every AI action runs through a human approval gate it cannot forge, leaves an Ed25519-signed receipt, and runs locally on 127.0.0.1 with your model keys. Governed by construction — and cheap because we’re not standing between you and your provider.
AI proposes
wants to act
Stage
dry-run · 0 writes
Policy
rules gate it
Sign
Ed25519
Approve
human clicks
Receipt
signed · verified
{
"receipt_id": "rc_9f4c2e…",
"flow": "client_sync",
"actor": "sami@localhost",
"airlock_status": "SECURE",
"sockets": 0,
"integrity_root": "sha256:c4f1…",
"approver": "human · signed",
"signature": "ed25519:…",
"verified_offline": true
}AI proposes
wants to act
Stage
dry-run · 0 writes
Policy
rules gate it
Sign
Ed25519
Approve
human clicks
Receipt
signed · verified
{
"receipt_id": "rc_9f4c2e…",
"flow": "client_sync",
"actor": "sami@localhost",
"airlock_status": "SECURE",
"sockets": 0,
"integrity_root": "sha256:c4f1…",
"approver": "human · signed",
"signature": "ed25519:…",
"verified_offline": true
}100% HIPAA compliant. Not paperwork — evidence.
Every HIPAA §164.312 technical safeguard is mapped, implemented, and provable in the product — not filed away in a policy binder. Protected health information never has to leave your infrastructure: the data plane is loopback, PHI is read, transformed, and governed at 127.0.0.1, and RailCall itself never receives it. That design is why we can be direct: the only unfinished piece is the letter from the auditor, and that audit is actively in progress. Everything underneath — access control, integrity, transmission, audit trail — is live today and you can point at it.
Access control
BYOK keys in a 0600 vault, resolved only on-box; every consequential action needs a terminal-only keypair approval the browser never sees.
Audit controls
Every action emits an Ed25519-signed, hash-chained receipt. Tamper any past entry and the chain breaks — evidence, not a log you have to trust.
Integrity
The approved bytes provably equal the fired bytes. Drift, a stale plan, or a bad signature fail closed — nothing executes.
Transmission
The highest-risk transfer — PHI leaving your network — simply doesn't happen. What reaches a model is your choice, under your own BAA.
SaaS sold seats. AI sells labor.
The wall in between is what RailCall solves.
AI agents deliver outcomes, not tools — the pricing unit is the action completed, not the seat that opened the app. But cloud agents can't scale into the enterprise because two things break immediately.
Local execution + cryptographic receipts. Not a wrapper, not a gateway — the layer that makes governed AI labor actually deployable past a CISO review.
Same task. Two bills.
One dev workflow, priced two ways. Cloud AI meters every step at frontier rates — reading files, running tests, re-sending your whole repo as context, retrying failed runs. RailCall runs all of that on the machine you already own, at 127.0.0.1, for $0. You pay a frontier model for exactly one thing: the reasoning.
Almost nothing leaves your machine.
Everything inside the box runs on loopback. The only two paths off the machine are reasoning tokens to a model you chose, and — on the paid tier — a signed API-key handshake that pulls a library primitive. No run-count ping, no workflow data. Your keys, source, and records never cross the line.
One workflow. 1,333 governed nodes. One signed root.
A deterministic corpus of governed workflows was run through the real engine — every node policy-gated, the entire blast radius folded into one plan, and that plan Ed25519-signed and offline-verified. The declared ceiling is 5,000 nodes; the proof reaches 1,333 in a single workflow.
Why the number matters: a real-world enterprise workflow routinely fans out past 500 governed steps (invoice batch, tenant sync, incident triage). 1,333 in one plan means we can hold your whole flow — not just a demo excerpt — under one signed receipt.
Three tiers. Frontier tokens only for the last one.
The biggest saving isn't a local LLM — it's the deterministic layer digesting a 200KB codebase down to a few KB of exact context before a paid model ever sees it. That saving is free, exact, and the hardest thing for anyone to copy.
Deterministic
free · 0 tokens · exactFind symbols, read files, map dependencies and tests — AST + index work, not even a model. It can't hallucinate, and it beats every alternative because it's free.
- ✓Symbol & reference search
- ✓Dependency & call graphs
- ✓Context packed to a few KB
Local model
cheap · on your hardwareThe fuzzy calls — "which of these is the auth function," "summarize this file in two lines" — handled by a small local model so the frontier model never has to.
- ✓Ambiguous-match triage
- ✓File / diff summarization
- ✓Runs on your box, no cloud
Frontier model
paid · rare · your keyThe actual plan and the actual code, on your BYOK key. It receives a small pre-digested bundle instead of a raw folder dump — so you pay frontier rates only for real reasoning.
- ✓The plan & the diff it writes
- ✓Pre-digested context in
- ✓Signed receipt out
Token-metered agent framework
RailCall — local free · protocol metered
Illustrative model, not a measured benchmark. Actual savings vary by workload, local-execution share, and rework prevented. We publish the calculator, not just the headline.
Prompt to signed receipt — on 127.0.0.1.
Watch the Studio execute a real governed workflow, from a natural-language prompt to a cryptographically signed receipt, entirely on your machine. Your data. Your proof.
Your compliance surface, drawn live.
Receipts stop being raw JSON and become a picture a CTO or auditor reads at a glance: an unbroken hash-chain, live workflow approvals with their full blast radius, a measured airlock, and a running tally of what the local layer saved.
Airlock radar
Context savings
When you build a workflow, you choose the permissions.
Every step declares an action class. You decide what runs itself and what waits for you — but the hard floors can't be widened: anything irreversible or that moves money always requires a human, no matter what the policy says.
The policy is itself a governed write. An agent can never loosen its own leash. A standing rule — "auto-approve reversible updates under a limit, always stop for anything irreversible or money" — stages, gets approved with the terminal APPROVE code, and lands as a signed receipt.
{ "policy_id": "pol_widen_01",
"widens": "reversible.under_limit",
"approver": "sami@localhost",
"signature": "ed25519:…" }RailCall for VS Code.
A sidecar to Copilot, Cursor, Claude Code — not a competitor.
Whatever AI you already use to write code, RailCall governs what it actually does. The extension surfaces the local airlock in-editor: a Pending Approvals tree you clear with one click, a live Receiptsfeed you can verify offline, and a status-bar chip showing pending count + today's receipts at a glance. No chat window, no third opinion on your suggestions — just the trust layer that catches every consequential action.
$ curl -fsSL https://railcall.ai/install.sh | bashIn VS Code: Cmd+Shift+P → Extensions: Install from VSIX… → select the downloaded file. Cmd+Shift+L opens the HUD.
Now shipping · Model Context Protocol (MCP) — drive RailCall from Claude Desktop, Cursor, and any MCP client; MCP-staged workflows surface right here in Pending Approvals with their full blast radius
Governance that also saves money
RailCall pays for itself four ways. The governance is why buyers install it. The math is why finance signs off.
Bring your own keys — RailCall takes zero cut of AI spend. Hosted-AI vendors typically add 30–100% markup on top of the same tokens. On a $1k/mo AI bill, that's $300–1000/mo back.
$100/seat/month whether you run 10 workflows a day or 10,000. No bill shock at end of month, no burst charges on a busy week.
Every irreversible write goes through preview → approve → execute. A bad batch caught in dry-run costs nothing. Caught in production it costs refunds, apologies, engineering time, and a client meeting nobody wants.
Signed, vetted integrations for CRM, billing, support, DevOps — free or single-digit-dollars each. An in-house Zendesk or HubSpot connector runs $15k–40k in engineering time you don't have to spend.
A founder who's done the hard exit — building the next one in the open.
RailCall is led by an operator who has already built and sold a company through real diligence, paired with an engineering team shipping the governed engine release by release.
Patrick Linden
Founder of Atlantic Energy (scaled across 36 utilities). Operator who raised a $75M debt facility (Signature Bank / V3) and led the exit at Gainline Partners. Builds for teams where data integrity and compliance must be verifiable, not assumed.
Sami Ben Chaalia
Senior full-stack + AI engineer — 'MVPs in Days'. Ships across the RailCall stack alongside the team: runtime, airlock, marketplace, Studio. Previously co-founder & CTO at Tynass IT, elected top-3 AI startup in Africa at Afric'up 2019 (Tunis) among 1,400 participants from 42 countries.
Kyle Burke
Runs finance and the commercial model — pricing, unit economics, and the path from free-local adoption to enterprise revenue.
Nick Capozzo
Runs operations and go-to-market — the developer community, launches, and getting RailCall in front of the teams who need it.
Free to run. We monetize the trust layer.
The whole local runtime is free — download it, run unlimited workflows, keep every credential on your machine. We make money on the layer around it: a marketplace with a 5% take-rate (creators keep 95%) and enterprise governance for teams whose CISO needs central policy, audit, and spend controls. Runtime is never metered on any tier, ever.
Free
- The uncrippled local engine + Studio
- Unlimited local runs — never metered
- Signed Ed25519 receipt per action
- Hash-chained tamper-evident audit trail
- BYOK provider keys, 0600 vault
- Nothing leaves 127.0.0.1
Team
- Everything in Free, for your whole team
- Multi-seat + RBAC (5 roles: owner / admin / publisher / operator / viewer)
- SSO — Okta, Azure AD, Google Workspace, any SAML/OIDC
- SCIM directory sync — auto-add/remove on IdP events
- Configurable receipt vault (local · S3 · NFS · custom)
- Admin audit log for every mutation
- Long-lived API keys for CI/CD publishing
Enterprise
- Everything in Team
- Signed BAA (HIPAA), DPA (GDPR)
- Air-gap install path (offline tarball)
- Contractual SLA + incident response commitment
- Direct support channel + dedicated engineer
- Custom vault driver + SCIM group→role mapping done for you
What's in every tier
| Feature | Free | Team | Enterprise |
|---|---|---|---|
| Runtime | |||
| Local Studio + engine (unmetered) | ✓ | ✓ | ✓ |
| Ed25519-signed receipts (per action) | ✓ | ✓ | ✓ |
| Hash-chained audit trail | ✓ | ✓ | ✓ |
| Airlock — human approval on every write | ✓ | ✓ | ✓ |
| BYOK provider keys (0600 vault) | ✓ | ✓ | ✓ |
| Marketplace install (free listings) | ✓ | ✓ | ✓ |
| Team & access | |||
| Seat minimum | 1 | 2 | Negotiated |
| Multi-seat + RBAC (5 roles) | — | ✓ | ✓ |
| SSO (Okta / Azure AD / Google / SAML / OIDC) | — | ✓ | ✓ |
| SCIM directory sync (auto add/remove) | — | ✓ | ✓ |
| Admin audit log (every mutation) | — | ✓ | ✓ |
| Long-lived API keys for CI/CD | — | ✓ | ✓ |
| Org-internal listings (private catalog) | — | ✓ | ✓ |
| Compliance | |||
| HIPAA §164.312 technical safeguardsEvery tier ships the same technical controls. | ✓ | ✓ | ✓ |
| Signed BAA (HIPAA) | — | — | ✓ |
| DPA (GDPR) | — | — | ✓ |
| Configurable receipt vault (S3 / NFS / custom) | — | ✓ | ✓ |
| Air-gap install kit (offline tarball) | — | — | ✓ |
| Data export (JSON + receipts) | ✓ | ✓ | ✓ |
| Support & guarantees | |||
| Community Discord | ✓ | ✓ | ✓ |
| Contractual SLA + incident response | — | — | ✓ |
| Dedicated support engineer | — | — | ✓ |
| Custom SCIM group→role mapping | — | — | ✓ |
| Free trial | — | 14 days | By arrangement |
The runtime is free, always. · Every tier ships the same signed-receipts + airlock + local execution. Team + Enterprise buy team seats, admin surfaces, and enterprise compliance signals — not different capabilities.
Each phase sells a bigger unit of value
— on the same local, provable rails.
Platform roadmap · workflows → modules → compute
Workflow Marketplace
Signed workflow primitives cleared on our rail. Live: publish + install pipe, creator payouts, reviews + ratings, live-mode Stripe subscriptions, Local DRM (per-install signed licenses).
Browse the marketplace →Module Marketplace
Domain experts publish whole vertical AI modules — signed handler bundles that register as new airlock commands. Local DRM binds each subscription cryptographically to one install: recurring ARR on self-hosted software, cryptographically enforced. First module live: Salesforce CRM — 20 airlock commands, $199/month, every write signed. Governs what your AI does INTO Salesforce; doesn't try to replace it.
See Salesforce module ($199/mo) →Phases 2–3 are directional. Sequencing is the strategy: workflows seed the marketplace, modules turn it into recurring vertical-software revenue, the installed base becomes the compute network — all on the same local-first, receipt-backed rails shipping in Phase 1.
Buy signed workflows. Sell yours.
Every listing is Ed25519-signed and pinned in the receipt ledger. Install with one command. Creators keep 95% — RailCall takes a 5% platform fee and pays out on demand.
Download RailCall Studio. Run your first governed flow in minutes.
Free forever for one — unlimited local runs. No card. Runs on your machine. You own the code — even after you cancel.
We are simply the protocol. Download and run the full local Studio — you own the UI, workflows, primitives, everything. Customize whatever you want.
or curl -fsSL https://railcall.ai/install.sh | bash
If we can't prove it, we don't claim it.
- ● liveFree local execution, signed receipts, offline verify, the four floors, dual-control, hash-chained journal. Red-teamed and holding — this is the moat.
- ● liveDeterministic code intelligence — symbol search, dependency & call graphs, test mapping. Zero tokens, no hallucination.
- ◇ roadmapTier-2 local-model routing and hosted library resolution. Architected, not yet shipped — shown as direction, not fact.
- ◇ roadmapThe visual Ledger Monitor & savings counter. This screen is a design preview; savings shown are modeled, not billed.
UNKNOWN means unverified — not a pass. Safe by default: RailCall runs in dry-run / proof mode. No live send, charge, or settlement happens unless you approve it.