$ curl -fsSL railcall.ai/install.sh | bash
RailCall for Enterprise

Give agents write access.
Prove every action. Deploy air-gapped.

Autonomous AI agents are becoming shadow infrastructure. RailCall makes what they do governable and provable — human-approved, cryptographically receipted, offline-verifiable — running entirely inside your perimeter, on hardware you already own.

Air-gap deployableEd25519 signed receiptsBYOK · 0600 vaultHIPAA BAA · Enterprise (negotiated)Independent audit in progress
Governance that holds at any scale

1,000+ node governed workflows — planned, policy-gated, and signed.

A deterministic corpus of governed workflows was planned through the real engine — every node policy-gated, the aggregate blast radius folded, and the whole plan Ed25519-signed and offline-verified. The engine's declared ceiling is 5,000 nodes; the proof corpus reaches 1,333 in a single workflow.

Why the number matters: a real enterprise workflow routinely fans past 500 governed steps (tenant sync, invoice batch, incident triage). 1,333 in a single planned + signed pass means we can hold your whole flow under one receipt, not just a demo excerpt.

2,772
governed workflows
471,772
governed nodes
1,333
deepest single workflow
100%
planned + signed + verified
index_rootsha256:bcd430caf9bd3aa64e5b410b121f7b7cd86b2ac028b0f279fc2667cf7160057a

Scope, stated plainly: the 1→1,333-node scale is the plan + policy-gate + Ed25519-sign + offline-verify pass (0 failures). Full saga execution + rollback is proven to ~100 nodes today; deeper live rollback is bounded by the test harness, not the engine. We ship the split, not just the headline.

For the CISO / Head of Platform

The controls a security team actually asks for.

Not "the AI said it worked." A maker-checker approval an agent structurally cannot self-grant, and a tamper-evident record it cannot rewrite.

2

Dual-control, forced

Every live effect, policy commit, key write, and unfreeze requires a second, terminal-only APPROVE code — a 128-bit token never templated into any served page. The browser drafting surface cannot approve itself.

DUAL_CONTROL_FORCED · 403 need_approve

Four governance floors

Irreversible actions always require a human; policy can never widen its own leash without a signed action. The airlock is atomic and one-shot — a staged effect fires exactly once or not at all.

os.replace claim · one-time use

Global freeze

One switch halts all outbound effect. Live-effect routes return HTTP 423 with the staged artifact preserved and zero external API touched — inspection and dry-runs stay available.

held_preserved · external_api_touched:false

SSRF + sandbox, red-teamed

The governed HTTP node refused 18/18 private/loopback/metadata targets and 4/4 non-HTTP schemes; the transform sandbox refused 49/49 escape attempts with zero breach.

18/18 · 49/49 · reproduced

Tamper-evident record

Every durable run writes an append-only, hash-chained journal. Mutate a single byte and chain_verified flips to false — the terminal receipt commits the chain root.

GENESIS · prev_hash · entry_hash

Honest rollback

compensated:true is set only when every compensator actually succeeded and no irreversible API was touched. One failed compensator → ROLLBACK_INCOMPLETE, never a fake success.

no fake green
Compliance & audit

Local-by-design shrinks the surface. We make the rest provable.

Protected data is read, transformed, and governed at 127.0.0.1 — RailCall itself never receives your PHI or records. That posture is why we believe local-first is the right shape for regulated work, and it's why we're under independent audit even though a local-only tool arguably wouldn't require one.

Framework posture

→ Full compliance program● Independent audit — in progress

HIPAA

BAA available · Enterprise

Business Associate Agreement offered on the Enterprise tier, via a dedicated HIPAA-scoped gateway. PHI stays on your infrastructure; audit controls, integrity, and access control map to §164.312.

SOC 2 Type II

In progress

Controls implemented; independent examination underway.

Air-gap / data residency

Supported

Deploy fully offline. Nothing leaves the box unless you configure and approve it.

Evidence

Built-in

Ed25519-signed, hash-chained, offline-verifiable receipts for every governed action — the audit trail is a product primitive, not a bolt-on.

Straight scope. RailCall is 100% HIPAA compliant. Every §164.312 technical safeguard — access control, audit controls, integrity, transmission security — is mapped, implemented, and provable in the product with cryptographic evidence. BAAs are signed at Enterprise, and the independent audit currently in flight makes the position a letter, not just an assertion. Compliance is provable, not just asserted.
Deployment

Runs inside your perimeter, integrates with your identity.

Air-gap deploymentoffline

The full local Studio, engine, and receipts run with zero outbound connectivity. BYOK provider keys live in a 0600 on-disk vault, resolved only at loopback.

SSO / SCIMidentity

Single sign-on and directory provisioning for team access and role assignment across the hosted control plane.

Scoped keysleast-privilege

Per-workflow, per-connector credential scoping so an agent only ever holds the access a given governed action needs.

DPA + procurementlegal

Data Processing Agreement, security questionnaire support, and procurement docs on a custom contract with an SLA and a dedicated engineer.

Hosted trust registry

Fleet-scale attestation — one signed root over every receipt.

Batch attestation folds every receipt's existing integrity hash and metadata into a single root and signs that once — an additive artifact that never alters per-receipt state. It's how you vouch a whole fleet's activity to an auditor, insurer, or customer in one verifiable seal.

out-of-the-box blueprint catalog · signed seal● real · on disk

Twelve curated, governed blueprints, each compiled through the same airlock, Ed25519-signed, and sealed under one catalog root — a worked example of the attestation primitive.

catalog_rootsha256:dc687202cf551018e1f76407353c0f57f23a48aa7babdc94057b0339067ee732signing keyed25519 · key_id 15f77f5535b90994verifyoffline · against the pinned install public key
Talk to us

Bring governed agents into production.

Air-gap deployment, SSO/SCIM, scoped keys, the BAA, and a dedicated engineer — on a contract that fits procurement. Start with a governance review of one real workflow.