$ curl -fsSL railcall.ai/install.sh | bash
RailCall
RailCall for Enterprise

Give agents write access.
Prove every action. Deploy air-gapped.

Autonomous AI agents are becoming shadow infrastructure. RailCall makes what they do governable and provable — human-approved, cryptographically receipted, offline-verifiable — running entirely inside your perimeter, on hardware you already own.

Air-gap deployableEd25519 signed receiptsBYOK · 0600 vaultHIPAA BAA · Enterprise (negotiated)Independent audit in progress
Governance that holds at any scale

1,000+ node governed workflows — planned, policy-gated, and signed.

A deterministic corpus of governed workflows was planned through the real engine — every node policy-gated, the aggregate blast radius folded, and the whole plan Ed25519-signed and offline-verified. The engine's declared ceiling is 5,000 nodes; the proof corpus reaches 1,333 in a single workflow.

2,772
governed workflows
471,772
governed nodes
1,333
deepest single workflow
100%
planned + signed + verified
index_rootsha256:bcd430caf9bd3aa64e5b410b121f7b7cd86b2ac028b0f279fc2667cf7160057a

Scope, stated plainly: the 1→1,333-node scale is the plan + policy-gate + Ed25519-sign + offline-verify pass (0 failures). Full saga execution + rollback is proven to ~100 nodes today; deeper live rollback is bounded by the test harness, not the engine. We ship the split, not just the headline.

For the CISO / Head of Platform

The controls a security team actually asks for.

Not "the AI said it worked." A maker-checker approval an agent structurally cannot self-grant, and a tamper-evident record it cannot rewrite.

2

Dual-control, forced

Every live effect, policy commit, key write, and unfreeze requires a second, terminal-only APPROVE code — a 128-bit token never templated into any served page. The browser drafting surface cannot approve itself.

DUAL_CONTROL_FORCED · 403 need_approve

Four governance floors

Irreversible actions always require a human; policy can never widen its own leash without a signed action. The airlock is atomic and one-shot — a staged effect fires exactly once or not at all.

os.replace claim · one-time use

Global freeze

One switch halts all outbound effect. Live-effect routes return HTTP 423 with the staged artifact preserved and zero external API touched — inspection and dry-runs stay available.

held_preserved · external_api_touched:false

SSRF + sandbox, red-teamed

The governed HTTP node refused 18/18 private/loopback/metadata targets and 4/4 non-HTTP schemes; the transform sandbox refused 49/49 escape attempts with zero breach.

18/18 · 49/49 · reproduced

Tamper-evident record

Every durable run writes an append-only, hash-chained journal. Mutate a single byte and chain_verified flips to false — the terminal receipt commits the chain root.

GENESIS · prev_hash · entry_hash

Honest rollback

compensated:true is set only when every compensator actually succeeded and no irreversible API was touched. One failed compensator → ROLLBACK_INCOMPLETE, never a fake success.

no fake green
Compliance & audit

Local-by-design shrinks the surface. We make the rest provable.

Protected data is read, transformed, and governed at 127.0.0.1 — RailCall itself never receives your PHI or records. That posture is why we believe local-first is the right shape for regulated work, and it's why we're under independent audit even though a local-only tool arguably wouldn't require one.

Framework posture

● Independent audit — in progress

HIPAA

BAA available · Enterprise

Business Associate Agreement offered on the Enterprise tier, via a dedicated HIPAA-scoped gateway. PHI stays on your infrastructure; audit controls, integrity, and access control map to §164.312.

SOC 2 Type II

In progress

Controls implemented; independent examination underway.

Air-gap / data residency

Supported

Deploy fully offline. Nothing leaves the box unless you configure and approve it.

Evidence

Built-in

Ed25519-signed, hash-chained, offline-verifiable receipts for every governed action — the audit trail is a product primitive, not a bolt-on.

Straight scope. HIPAA compliance is a posture of the covered entity, not a checkbox on any vendor's product — we do not declare you compliant, and we don't claim certifications we don't hold. We shrink your surface, offer the BAA, produce the cryptographic evidence, and are validating that position under an independent audit. We make compliance provable, not just asserted.
Deployment

Runs inside your perimeter, integrates with your identity.

Air-gap deploymentoffline

The full local Studio, engine, and receipts run with zero outbound connectivity. BYOK provider keys live in a 0600 on-disk vault, resolved only at loopback.

SSO / SCIMidentity

Single sign-on and directory provisioning for team access and role assignment across the hosted control plane.

Scoped keysleast-privilege

Per-workflow, per-connector credential scoping so an agent only ever holds the access a given governed action needs.

DPA + procurementlegal

Data Processing Agreement, security questionnaire support, and procurement docs on a custom contract with an SLA and a dedicated engineer.

Hosted trust registry

Fleet-scale attestation — one signed root over every receipt.

Batch attestation folds every receipt's existing integrity hash and metadata into a single root and signs that once — an additive artifact that never alters per-receipt state. It's how you vouch a whole fleet's activity to an auditor, insurer, or customer in one verifiable seal.

out-of-the-box blueprint catalog · signed seal● real · on disk

Twelve curated, governed blueprints, each compiled through the same airlock, Ed25519-signed, and sealed under one catalog root — a worked example of the attestation primitive.

catalog_rootsha256:dc687202cf551018e1f76407353c0f57f23a48aa7babdc94057b0339067ee732signing keyed25519 · key_id 15f77f5535b90994verifyoffline · against the pinned install public key
Talk to us

Bring governed agents into production.

Air-gap deployment, SSO/SCIM, scoped keys, the BAA, and a dedicated engineer — on a contract that fits procurement. Start with a governance review of one real workflow.