← RailGuard

Security

Last updated 29 September 2026

Data flow

  1. Agent → RailGuard API over HTTPS with a per-agent key (only a hash is stored).
  2. Policy evaluation runs server-side; results are stored in your workspace, isolated from other companies by database row-level security.
  3. If approved, a card or payment is requested from the rail you connected. Card details are stored once and wiped as soon as the agent collects them.
  4. Approval alerts go to your in-app inbox and your own Slack/Teams webhook.

Audit log

Audit rows are append-only: the database denies updates and deletes from every app user, including Admins. The only removals are the automatic retention purge for your plan (90 days Free/Team, 1 year Growth, as agreed on Enterprise) and resetting a Demo workspace.

Other controls

  • Role-based access: Admin, Approver, Viewer.
  • Secrets are kept server-side only, never in the browser.
  • Rate limiting on the agent API; signed decision webhooks (HMAC-SHA256).
  • Security headers (CSP, frame protection) on all pages.

We do not currently hold a SOC 2 or ISO 27001 certification.

Subprocessors

  • Cloud hosting and database provider — application hosting, storage, auth.
  • Paddle — subscriptions, payments and invoicing (Merchant of Record).
  • AI model provider — optional approval summaries, only when an Approver requests one.
  • Email delivery provider — account and notification emails.
  • Rails you connect (Stripe, Ramp, blockchain networks) and Slack/Teams channels you configure.

Deleting a workspace

Admins can reset Demo data any time in Settings. To delete a Live workspace or your account, send a request via the contact form on the Pricing page from an Admin email. UNICHAT-APP LTD deletes workspace data, including audit logs, within 90 days unless the law requires longer. Export your audit log first from Settings.

Reporting a vulnerability

See security.txt.