Version 2.0 · Last updated: August 27, 2026
Security by architecture. RailCall is designed to minimize attack surface by keeping your keys, code, and data on your machine. This page explains our security model, practices, and how to report vulnerabilities.
The core guarantee
When your AI does something on your behalf — sends an email, charges a card, updates a record — RailCall signs a cryptographic receipt of exactly what happened, by whom, and under which rules. Anyone can check that receipt is genuine and unaltered, offline, with our servers switched off. It's the same mathematics that secures your bank's website and every verified app-store download — the strongest guarantee cryptography can give.
“Unforgeable unless you hold the private key” isn't fine print — it's the definition of digital security. The padlock on your bank site (TLS), signed software updates, and signed source code all rest on that exact sentence. No honest system claims more: whoever holds a signing key can sign with it — that is what a key is for. So this is the maximal, honest claim — unforgeable by anyone who doesn't hold the key.
Two keys — and stealing one is not stealing the system
lives only on your machine · like your house key
Signs your receipts. If it were stolen, the thief could only act as your one account — and could never deny it, exactly like a stolen signature. Every other account stays untouched, and the key can be revoked.
held only by us · never on any machine
Does one job: vouch for which account a station belongs to. It cannot rewrite a single receipt that was already signed — not even a past one. It's the key we guard hardest: off every machine, rotated on a 90-day expiry, moving to hardware.
Bottom line:steal one station's key and you compromise one account — bounded, revocable, undeniable. No key anywhere, ours included, can alter a receipt your station has already signed or rewrite the past.
The authoritative list of the providers we actually use is the published subprocessor list, and it controls over anything on this page. It currently names Render, WorkOS, Stripe, Resend, GitHub, and Cloudflare. Our hosted services run on managed platform infrastructure with:
Every approved action mints a receipt with:
We hold no security or compliance certification. No SOC 2 report, no HIPAA certification, no PCI DSS attestation, no ISO 27001 certificate. Where this page names a target date, that is a target and not a report. Terms of Service §14.1 states the same thing contractually.
Previous versions of this page said otherwise— that RailCall is “100% compliant with the §164.312 technical safeguards today.” That claim is withdrawn in full. There is no such certification for a software vendor to hold, we do not hold one, and an unqualified compliance assertion is a representation we cannot support. What we can say is narrower and is set out below.
Scope note:The controls described on this page are product controls. Your organisation’s overall regulatory posture also depends on how you configure, deploy, and operate the product, and that part is yours. No property of our software makes your organisation compliant with anything. Consult your counsel or auditors on end-to-end coverage.
Counsel — SOC 2 and penetration-test wordingThe HIPAA claim is withdrawn site-wide in this change— this page, the Enterprise and Teams pages, and the four marketing components no longer assert compliance. What still needs review is the remaining audit language: “SOC 2 audit in progress” and any reference to annual third-party penetration testing should not be published unless there is an engagement letter or report behind each one.CounselConfirm the HIPAA §164.312 control mapping is published at a stable URL before this page points at it as an artifact — the changelog references a/trust/hipaa page. A mapping we describe but do not publish is the same defect in a quieter voice.If you discover a security vulnerability, please disclose it responsibly:
In scope:
Out of scope:
We don't run a cash bug-bounty program. Valid, high-impact reports earn contributor credit on our public community leaderboard, scaled to severity, plus a public acknowledgment in the fix advisory (with your permission, and never before a fix ships).
Violation of these rules may forfeit any recognition and result in legal action.
To maximize security when using RailCall:
No silver bullet. RailCall's local-first architecture reduces attack surface by minimizing data transmission, but it is not a complete security solution.
Our commitment: Operate transparently, patch quickly, and never hide incidents. Security is a journey, not a destination.
For security questions or concerns:
Email: sami@railcall.ai
Entity: AiTrade LLC, a Florida limited liability company
Counsel — registered addressCounsel supplied the jurisdiction of formation on 2026-08-27, and the entity block above now reads "AiTrade LLC, a Florida limited liability company". The registered business address was not supplied and is not published anywhere on this site — we have not invented one. Provide it. A security page is one an enterprise reviewer reads with a procurement checklist in hand, and a complete entity block is on it.Entity: AiTrade LLC, a Florida limited liability company · Last updated: July 14, 2026
See also: Privacy Policy · Terms of Service · Data Flow Disclosure