Security
Enterprise security, built in.
RailAI is built from the ground up with security, privacy and compliance at its core. Your data stays yours.
SOC 2 Type II
Audited annually by a top-four firm. Full report available under NDA.
GDPR Ready
Data processing agreements, right-to-erasure workflows and EU data residency options.
SSO / SAML
Enterprise single sign-on with SAML 2.0, SCIM provisioning and directory sync.
Encryption at Rest
AES-256 encryption for all data at rest. TLS 1.3 for all data in transit.
Data Handling
- All customer data is encrypted at rest using AES-256 and in transit using TLS 1.3.
- Personally identifiable information is tokenized and stored separately from analytics data.
- Data retention policies are configurable per workspace with automatic purge schedules.
- Full audit logs with tamper-proof storage for all data access and modification events.
Infrastructure
- Hosted on AWS with multi-region redundancy and 99.99% uptime SLA for Enterprise plans.
- Network isolation via VPC peering with no public-facing database endpoints.
- Automated vulnerability scanning and penetration testing on a quarterly cadence.
- Infrastructure-as-code with immutable deployments and automated rollback capabilities.
Compliance
- SOC 2 Type II certified with continuous monitoring through Vanta.
- GDPR compliant with Data Processing Agreements available for all EU customers.
- CCPA ready with automated data subject request handling.
- Regular third-party security assessments and bug bounty program.
Responsible AI
- All AI models are trained on licensed and consented data only.
- Content scoring models are audited for bias on a monthly cadence.
- Customer data is never used to train shared models without explicit opt-in.
- Transparent model cards published for all prediction endpoints.
Have a security question?
Our security team is available to answer questions, provide our SOC 2 report under NDA, or discuss your specific compliance requirements.
security@railai.cloud