Security

Claims we can prove

Every statement on this page corresponds to a rule enforced in the database or the server — not a setting someone remembered to turn on.

Architecture

SOC 2

Our SOC 2 report is available to customers and prospects under NDA — email [email protected] to request it.

Subprocessors

ProviderPurposeData
RailwayApplication hostingAll application data (encrypted at rest)
PostgreSQL (managed)DatabaseAll application data
CloudflareObject storage (R2), this siteUploaded documents, exports, backups
StripePayments, bank feeds, billingPayment and bank-feed data; billing details
SendGridEmail sending and inbound mailEmail addresses and message contents
Anthropic / OpenRouterModel inference for the agentsDocument text and ledger context sent for a task
SentryError monitoringError traces (no document contents)

Responsible disclosure

Found a vulnerability? Email [email protected]. We acknowledge within two business days, keep you informed, and credit you if you wish. Please do not access data that is not yours and do not run denial-of-service tests.