RailGuardDocs

Security

Developer view. The full policy is on the public Security page.

See /security and security.txt to report issues.

Data flow

Agent → HTTPS → RailGuard evaluates policies server-side → decision + audit row stored in your workspace (isolated by row-level security) → optional payout via your configured rail → webhook back to agent.

Key handling

  • Agent keys shown once, stored as SHA-256 hashes, revocable per agent.
  • Provider secrets are server-only, never sent to the browser.
  • Issued card details are released to the agent once, then wiped.

Verify a webhook

Node
import crypto from "node:crypto";
const key = crypto.createHash("sha256").update(apiKey).digest("hex");
const expected = crypto.createHmac("sha256", key).update(`${ts}.${rawBody}`).digest("hex");
const ok = Math.abs(Date.now()/1000 - Number(ts)) < 300 &&
  crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signature));

Subprocessors

  • Lovable Cloud (hosting, database, auth)
  • Paddle (billing)
  • Stripe / Ramp (only if you connect them)
  • AI Gateway (review summaries, only when an approver requests one)

Delete a workspace

An Admin requests deletion via the contact form; we confirm identity and delete workspace data, including audit rows.