Data flow
- Agent → RailGuard API over HTTPS with a per-agent key (only a hash is stored).
- Policy evaluation runs server-side; results are stored in your workspace, isolated from other companies by database row-level security.
- If approved, a card or payment is requested from the rail you connected. Card details are stored once and wiped as soon as the agent collects them.
- Approval alerts go to your in-app inbox and your own Slack/Teams webhook.
Audit log
Audit rows are append-only: the database denies updates and deletes from every app user, including Admins. The only removals are the automatic retention purge for your plan (90 days Free/Team, 1 year Growth, as agreed on Enterprise) and resetting a Demo workspace.
Other controls
- Role-based access: Admin, Approver, Viewer.
- Secrets are kept server-side only, never in the browser.
- Rate limiting on the agent API; signed decision webhooks (HMAC-SHA256).
- Security headers (CSP, frame protection) on all pages.
We do not currently hold a SOC 2 or ISO 27001 certification.
Subprocessors
- Cloud hosting and database provider — application hosting, storage, auth.
- Paddle — subscriptions, payments and invoicing (Merchant of Record).
- AI model provider — optional approval summaries, only when an Approver requests one.
- Email delivery provider — account and notification emails.
- Rails you connect (Stripe, Ramp, blockchain networks) and Slack/Teams channels you configure.
Deleting a workspace
Admins can reset Demo data any time in Settings. To delete a Live workspace or your account, send a request via the contact form on the Pricing page from an Admin email. UNICHAT-APP LTD deletes workspace data, including audit logs, within 90 days unless the law requires longer. Export your audit log first from Settings.
Reporting a vulnerability
See security.txt.