Give agents write access.
Prove every action. Deploy air-gapped.
Autonomous AI agents are becoming shadow infrastructure. RailCall makes what they do governable and provable — human-approved, cryptographically receipted, offline-verifiable — running entirely inside your perimeter, on hardware you already own.
1,000+ node governed workflows — planned, policy-gated, and signed.
A deterministic corpus of governed workflows was planned through the real engine — every node policy-gated, the aggregate blast radius folded, and the whole plan Ed25519-signed and offline-verified. The engine's declared ceiling is 5,000 nodes; the proof corpus reaches 1,333 in a single workflow.
Scope, stated plainly: the 1→1,333-node scale is the plan + policy-gate + Ed25519-sign + offline-verify pass (0 failures). Full saga execution + rollback is proven to ~100 nodes today; deeper live rollback is bounded by the test harness, not the engine. We ship the split, not just the headline.
The controls a security team actually asks for.
Not "the AI said it worked." A maker-checker approval an agent structurally cannot self-grant, and a tamper-evident record it cannot rewrite.
Dual-control, forced
Every live effect, policy commit, key write, and unfreeze requires a second, terminal-only APPROVE code — a 128-bit token never templated into any served page. The browser drafting surface cannot approve itself.
DUAL_CONTROL_FORCED · 403 need_approveFour governance floors
Irreversible actions always require a human; policy can never widen its own leash without a signed action. The airlock is atomic and one-shot — a staged effect fires exactly once or not at all.
os.replace claim · one-time useGlobal freeze
One switch halts all outbound effect. Live-effect routes return HTTP 423 with the staged artifact preserved and zero external API touched — inspection and dry-runs stay available.
held_preserved · external_api_touched:falseSSRF + sandbox, red-teamed
The governed HTTP node refused 18/18 private/loopback/metadata targets and 4/4 non-HTTP schemes; the transform sandbox refused 49/49 escape attempts with zero breach.
18/18 · 49/49 · reproducedTamper-evident record
Every durable run writes an append-only, hash-chained journal. Mutate a single byte and chain_verified flips to false — the terminal receipt commits the chain root.
GENESIS · prev_hash · entry_hashHonest rollback
compensated:true is set only when every compensator actually succeeded and no irreversible API was touched. One failed compensator → ROLLBACK_INCOMPLETE, never a fake success.
no fake greenLocal-by-design shrinks the surface. We make the rest provable.
Protected data is read, transformed, and governed at 127.0.0.1 — RailCall itself never receives your PHI or records. That posture is why we believe local-first is the right shape for regulated work, and it's why we're under independent audit even though a local-only tool arguably wouldn't require one.
Framework posture
● Independent audit — in progress| Framework | Status | How |
|---|---|---|
| HIPAA | BAA · negotiated at Enterprise | A Business Associate Agreement is drafted (aligned to 45 CFR § 164.504(e)(2)(ii)) and reviewed on request under NDA. Signed per-customer at the Enterprise tier after our counsel and yours agree the language. §164.312 technical safeguards implemented today (see security-review). PHI stays on your infrastructure — most deployments never make RailCall a business associate at all. |
| SOC 2 Type II | Targeting Q4 2026 | Working toward a SOC 2 Type II report by Q4 2026 with an independent CPA firm. Controls implemented today; ask for the current inventory and readiness posture — we send it under NDA to procurement teams. |
| Air-gap / data residency | Supported | Deploy fully offline. Nothing leaves the box unless you configure and approve it. |
| Evidence | Built-in | Ed25519-signed, hash-chained, offline-verifiable receipts for every governed action — the audit trail is a product primitive, not a bolt-on. |
HIPAA
BAA available · EnterpriseBusiness Associate Agreement offered on the Enterprise tier, via a dedicated HIPAA-scoped gateway. PHI stays on your infrastructure; audit controls, integrity, and access control map to §164.312.
SOC 2 Type II
In progressControls implemented; independent examination underway.
Air-gap / data residency
SupportedDeploy fully offline. Nothing leaves the box unless you configure and approve it.
Evidence
Built-inEd25519-signed, hash-chained, offline-verifiable receipts for every governed action — the audit trail is a product primitive, not a bolt-on.
Runs inside your perimeter, integrates with your identity.
Air-gap deploymentoffline
The full local Studio, engine, and receipts run with zero outbound connectivity. BYOK provider keys live in a 0600 on-disk vault, resolved only at loopback.
SSO / SCIMidentity
Single sign-on and directory provisioning for team access and role assignment across the hosted control plane.
Scoped keysleast-privilege
Per-workflow, per-connector credential scoping so an agent only ever holds the access a given governed action needs.
DPA + procurementlegal
Data Processing Agreement, security questionnaire support, and procurement docs on a custom contract with an SLA and a dedicated engineer.
Fleet-scale attestation — one signed root over every receipt.
Batch attestation folds every receipt's existing integrity hash and metadata into a single root and signs that once — an additive artifact that never alters per-receipt state. It's how you vouch a whole fleet's activity to an auditor, insurer, or customer in one verifiable seal.
Twelve curated, governed blueprints, each compiled through the same airlock, Ed25519-signed, and sealed under one catalog root — a worked example of the attestation primitive.
Bring governed agents into production.
Air-gap deployment, SSO/SCIM, scoped keys, the BAA, and a dedicated engineer — on a contract that fits procurement. Start with a governance review of one real workflow.