Skip to content

Security

Effective Date: July 27, 2026

1. Our Security Model

Every customer gets their own dedicated instance — a separate, hardened container with its own encrypted storage and its own private network — running on infrastructure we operate in the United States. Your agent runs there, and only there. Your documents and conversations are stored in our managed database, where every record carries your workspace’s identity and every query resolves that identity from your signed-in session rather than from anything the caller supplies — so one workspace cannot request another’s records. Your integration credentials go further: each workspace has its own encryption key, so they are not readable even with access to the stored data.

The short version:You get your own isolated instance, not a row in a shared database. Data is encrypted in transit and at rest, backed up daily and kept separately, and never used to train public AI models. We are also plain about what we don’t have yet — see section 10.

2. Tenant Isolation

Isolation is enforced at the infrastructure layer, not just in application logic. Each customer instance runs with:

3. Encryption

4. Authentication and Access Control

5. Data Handling and AI

Your agents run inference through contracted third-party AI providers. We send only what is needed to produce the requested output, and:

Every third-party provider we rely on, and the specific purpose each one serves, is listed on our sub-processors page.

Agents can act on your behalf — including sending email and posting to connected messaging channels. You are responsible for reviewing and approving communications that carry real consequences for your business or your clients.

6. Backups and Recovery

If you cancel, you have a 30-day window to export your data. After that window your instance and its data are deleted.

7. Monitoring and Logging

8. Vulnerability Disclosure

If you have found a security issue in Raileon, we want to hear about it. Email security@raileon.com with enough detail for us to reproduce the problem — the affected URL or endpoint, the steps you took, and what you observed.

In scope

Out of scope

What we ask

Our commitment: We will acknowledge your report within 3 business days and keep you updated while we investigate. We will not pursue legal action against researchers who act in good faith and follow this policy.

9. Incident Response

If we confirm a security incident affecting your data, we will notify you without undue delay. Where the incident is a personal-data breach, we will notify affected customers within 72 hours of confirming it, and we will tell you what we know, what we don’t yet know, and what we are doing about it — rather than waiting until the picture is complete. The full contractual terms are in our Data Processing Addendum.

10. Compliance Status

Plenty of vendors imply certifications they don’t hold. Here is exactly where Raileon stands today:

This is a statement of where we are now, not a position we intend to hold forever. We would rather tell you the truth than let you assume an audit exists. If your procurement process requires any of the above, tell us early at security@raileon.com so you can make an informed decision.

11. Contact

Security reports and questions: security@raileon.com
Data-protection matters: privacy@raileon.com
Everything else: admin@raileon.com

Raileon LLC
Miami, Florida