$ curl -fsSL railcall.ai/install.sh | bash
For teams · 5–50 seats

Deploy RailCall across your team — your keys, your SSO, your seats.

Everyone on your team gets governed AI writes on their machine. SSO through your identity provider, RBAC across five roles, private modules only your team sees, signed receipts streamed to your vault. Self-serve — no sales call required to start.

Team tier
Governed AI writes, across your team.
$100
/ seat / month · min 2 seats · 14-day free trial
Every seat gets
  • Studio + CLI + VS Code extension per seat
  • SSO via WorkOS (Okta, Azure AD, Google, Ping)
  • 5-role RBAC + SCIM directory sync
  • Private modules — visible only to your team
  • Shared receipt vault (local · S3 · SMB/NFS · custom driver)
  • Admin audit log + org data export (GDPR Art. 20)
  • Long-lived API keys for CI/CD publishing
  • Priority Discord + email support

No card required to start · card required on day 14 to keep the team going · cancel anytime from Stripe billing portal at /marketplace/org/billing.

Enterprise capabilities · every Team-tier seat

Every surface a team-admin needs, wired end-to-end.

Identity
SSO via your IdP

SAML / OIDC through WorkOS. Okta, Azure AD, Google Workspace, Ping. Your users type your domain, browser bounces through your IdP, we mint the JWT. Zero password reuse.

/marketplace/sso
Roles
5-role RBAC + SCIM

viewer / operator / publisher / admin / owner. Higher implicitly grants lower. WorkOS webhook mirrors IdP changes — flip a user in Okta, membership updates within 15 min.

/marketplace/org/members
Modules
Private modules — team-only

Publish internal modules that only your org's Studio installs can see. Public marketplace never lists them. Same signing + license machinery as public modules, gated on org membership.

Enterprise plan · Week 8
Receipts
Shared vault, 4 drivers

local (filesystem / NAS / USB) · s3 (also MinIO, R2, GCS) · SMB/NFS network share · custom loader for your compliance layer. Secrets never in our DB — env:/file:/keyring: references.

/marketplace/org/vault-config
Deploy
Air-gap install kit

Self-contained tarball with every file + governance ruleset + station bundle + MANIFEST.txt sha256 + verify.sh. Move to network-isolated host, run verify + install. No outbound at install OR runtime.

/trust/air-gap
Audit
Admin audit log

Append-only. Every admin mutation (invite, role change, vault reconfigure, subscription event) is a signed row. Owner+ view with event-slug filter + keyset pagination. Exportable for compliance.

/marketplace/org/audit
What every seat gets
100% on 127.0.0.1BYOK · no per-execution feesEd25519 signed receiptsHIPAA compliantAir-gap deployableSOC 2 audit in progress

Full trust surface at /trust · subprocessors at /trust/subprocessors · live status at /status.

Enterprise
Need something the self-serve tier doesn't cover?

50+ seats · negotiated BAA · air-gap install · custom retention · SOC 2 documentation under NDA · dedicated onboarding · custom vault drivers. Same code, formal contract.