Security
Developer view. The full policy is on the public Security page.
See /security and security.txt to report issues.
Data flow
Agent → HTTPS → RailGuard evaluates policies server-side → decision + audit row stored in your workspace (isolated by row-level security) → optional payout via your configured rail → webhook back to agent.
Key handling
- Agent keys shown once, stored as SHA-256 hashes, revocable per agent.
- Provider secrets are server-only, never sent to the browser.
- Issued card details are released to the agent once, then wiped.
Verify a webhook
Node
import crypto from "node:crypto";
const key = crypto.createHash("sha256").update(apiKey).digest("hex");
const expected = crypto.createHmac("sha256", key).update(`${ts}.${rawBody}`).digest("hex");
const ok = Math.abs(Date.now()/1000 - Number(ts)) < 300 &&
crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signature));Subprocessors
- Lovable Cloud (hosting, database, auth)
- Paddle (billing)
- Stripe / Ramp (only if you connect them)
- AI Gateway (review summaries, only when an approver requests one)
Delete a workspace
An Admin requests deletion via the contact form; we confirm identity and delete workspace data, including audit rows.