Version 1.0 · Last updated: July 14, 2026
Security by architecture. RailCall is designed to minimize attack surface by keeping your keys, code, and data on your machine. This page explains our security model, practices, and how to report vulnerabilities.
RailCall gateway and seat-validation services run on AWS (or GCP), leveraging:
Every approved action mints a receipt with:
Important: RailCall does not make blanket "SOC2 compliant" or "HIPAA exempt" claims. Your regulatory posture depends on your specific use case and must be determined by you (or your counsel/auditors).
If you discover a security vulnerability, please disclose it responsibly:
In scope:
Out of scope:
We offer recognition and compensation for valid, high-impact vulnerabilities:
Payouts are at AiTrade's discretion based on impact, exploitability, and quality of report.
Violation of these rules may disqualify you from bounty and result in legal action.
To maximize security when using RailCall:
No silver bullet. RailCall's local-first architecture reduces attack surface by minimizing data transmission, but it is not a complete security solution.
Our commitment: Operate transparently, patch quickly, and never hide incidents. Security is a journey, not a destination.
For security questions or concerns:
Email: security@railcall.ai
PGP Key: railcall.ai/.well-known/security.txt
Entity: AiTrade LLC
Entity: AiTrade LLC · Last updated: July 14, 2026
See also: Privacy Policy · Terms of Service · Data Flow Disclosure