Security
Effective Date: July 27, 2026
1. Our Security Model
Every customer gets their own dedicated instance — a separate, hardened container with its own encrypted storage and its own private network — running on infrastructure we operate in the United States. Your agent runs there, and only there. Your documents and conversations are stored in our managed database, where every record carries your workspace’s identity and every query resolves that identity from your signed-in session rather than from anything the caller supplies — so one workspace cannot request another’s records. Your integration credentials go further: each workspace has its own encryption key, so they are not readable even with access to the stored data.
2. Tenant Isolation
Isolation is enforced at the infrastructure layer, not just in application logic. Each customer instance runs with:
- A dedicated container per customer— one instance, one customer, no shared runtime.
- A hardened container runtime— we use a sandboxed runtime that intercepts system calls in user space rather than passing them straight to the host kernel, which shrinks the surface a container breakout would have to attack.
- A per-customer private network— instances cannot see or reach each other.
- An encrypted volume— your instance’s persistent storage is encrypted at the disk layer.
- A read-only filesystem— the container image itself cannot be modified at runtime; writes are confined to the explicit data volume.
- A restricted syscall profile— a custom allowlist limits which kernel operations the container can perform at all.
- Non-root execution— nothing inside your instance runs as a privileged user.
- Per-customer resource limits— CPU and memory are capped per instance, so one customer running a heavy workload cannot degrade anyone else’s service.
3. Encryption
- In transit: All traffic between your browser, our application, your instance, and any third-party service is encrypted with TLS 1.2 or higher.
- At rest: Stored data is encrypted using AES-256.
4. Authentication and Access Control
- Managed identity provider: Sign-in, sessions, and credential storage are handled by a specialist third-party identity provider. We do not store your password, and we do not roll our own session handling.
- Organization-scoped access:Users belong to an organization, and every request is checked against the caller’s organization before any data is returned. Access is derived from the verified session, never from an identifier supplied by the browser.
- Role tiers:Members of an organization hold one of three roles — owner, admin, or member — which determine what they can view and change.
- Audited staff support access: When Raileon support staff need to look at your workspace to resolve an issue, they do so through a dedicated, explicitly marked support session that is recorded. Staff access is limited to what is needed to do the job.
5. Data Handling and AI
Your agents run inference through contracted third-party AI providers. We send only what is needed to produce the requested output, and:
- Customer data is never used to train public AI models.
- Training is disabled on the provider APIs we use, under the terms of our agreements with them.
- Providers process your data to serve the request and are contractually restricted in what else they may do with it.
Every third-party provider we rely on, and the specific purpose each one serves, is listed on our sub-processors page.
Agents can act on your behalf — including sending email and posting to connected messaging channels. You are responsible for reviewing and approving communications that carry real consequences for your business or your clients.
6. Backups and Recovery
- Daily, per-customer backupsof your instance’s data.
- Stored separately from the running instance, so a failure of the primary host does not take the backups with it.
- 30-day retention.
- Periodic restore drills— we restore from backup on a recurring schedule, because a backup you have never restored is not a backup.
If you cancel, you have a 30-day window to export your data. After that window your instance and its data are deleted.
7. Monitoring and Logging
- Structured application logging across the platform, so activity can be traced and reviewed.
- Centralised log aggregation— logs are shipped to a central store where they can be searched and alerted on.
- Error monitoring— application errors and exceptions are captured and surfaced to our team automatically.
8. Vulnerability Disclosure
If you have found a security issue in Raileon, we want to hear about it. Email security@raileon.com with enough detail for us to reproduce the problem — the affected URL or endpoint, the steps you took, and what you observed.
In scope
- raileon.com and the Raileon web application.
- The Raileon API.
- The customer instances we operate, including anything that would let one customer reach another customer’s data.
Out of scope
- Third-party services we use but do not control — report those to the provider directly.
- Reports generated purely by an automated tool with no demonstrated impact.
- Missing best-practice headers or configuration with no exploitable consequence.
- Social engineering of Raileon staff or customers.
What we ask
- Please do not run automated scanners, fuzzers, or brute-force tooling against our systems.
- Please do not degrade service, exfiltrate data, or access an account that isn’t yours. If you stumble into someone else’s data, stop and tell us.
- Please give us a reasonable window to fix the issue before disclosing it publicly.
9. Incident Response
If we confirm a security incident affecting your data, we will notify you without undue delay. Where the incident is a personal-data breach, we will notify affected customers within 72 hours of confirming it, and we will tell you what we know, what we don’t yet know, and what we are doing about it — rather than waiting until the picture is complete. The full contractual terms are in our Data Processing Addendum.
10. Compliance Status
Plenty of vendors imply certifications they don’t hold. Here is exactly where Raileon stands today:
- SOC 2 — not completed. Raileon has not undergone a SOC 2 Type I or Type II audit, and we have no SOC 2 report to share.
- ISO 27001 — not certified. We are not ISO 27001 certified.
- Penetration test — none published. We have not commissioned or published a third-party penetration test report.
- HIPAA — no BAA offered.Raileon does not sign Business Associate Agreements and is not a HIPAA-compliant platform. Do not send protected health information to Raileon — this is also covered by our Acceptable Use Policy.
This is a statement of where we are now, not a position we intend to hold forever. We would rather tell you the truth than let you assume an audit exists. If your procurement process requires any of the above, tell us early at security@raileon.com so you can make an informed decision.
11. Contact
Security reports and questions: security@raileon.com
Data-protection matters: privacy@raileon.com
Everything else: admin@raileon.com
Raileon LLC
Miami, Florida