Trust, security, and DSGVO compliance
EU-only data processing on Hetzner Germany. Encrypted credentials, MFA-TOTP, nonce-based CSP, audit logging, and provider failover â shipped by default for every customer.
Compliance
DSGVO / GDPR compliance
Railwail is a German-incorporated controller / processor for customer data under the EU GDPR (and its DSGVO transposition). Compliance is engineered into the platform, not bolted on at billing time.
Every API request, every credential, every audit log, every dollar of usage data is processed and stored inside the European Union. Our primary infrastructure runs on Hetzner Germany. We do not ship customer data outside the EEA without explicit per-tenant configuration.
A signed DPA (GDPR Art. 28) is available on request for every paying customer. The DPA covers sub-processor disclosure, breach notification windows, audit rights, and standard contractual clauses for any unavoidable extra-EU transfer.
The full sub-processor inventory is published and versioned. We notify subscribers at least 30 days before adding or replacing a sub-processor that touches customer data.
Self-serve export and deletion of personal data are available from the account dashboard. Article 15 (access) and Article 17 (erasure) requests are fulfilled within the statutory 30-day window â usually within 24 hours.
Security
Platform security
The defaults are conservative â TLS-only transport, encrypted-at-rest credentials, nonce-based CSP, and a tamper-evident audit log. We assume every request could be hostile and we measure ourselves against that.
Audit in progress. Trust-services criteria mapping, control evidence collection, and observation-period start date are tracked internally; status updates land here and on the changelog.
All traffic â marketing pages, API endpoints, dashboard, billing portal â is served over TLS 1.3 with HSTS preload, OCSP stapling, and modern cipher suites. Plain HTTP redirects 308 to HTTPS with no exception.
Every server-rendered page emits a strict Content Security Policy with per-request nonces. Inline scripts and styles cannot execute without the matching nonce, neutralising the most common XSS vectors even if user-generated content is rendered downstream.
Multi-factor authentication via TOTP (RFC 6238) is available for every account and enforceable at the workspace level for teams. WebAuthn / passkeys are on the roadmap.
API keys, OAuth refresh tokens, and provider credentials are encrypted at rest with AES-256-GCM using envelope encryption. Database backups inherit the same encryption and never leave the EU.
Every privileged action â key creation, billing change, member invite, model invocation by API key â is appended to an immutable audit log scoped per tenant. The log is queryable by admins and exportable in JSON / CSV.
Privacy
Data handling & retention
Customer prompts and outputs are the customer's data. We minimise retention by default, give administrators a self-serve UI for exports and deletes, and never feed customer data into model training.
By default, prompts and outputs are retained 90 days for abuse-prevention and billing-dispute resolution, then deleted on a rolling cron. Enterprise customers can configure shorter (or longer) windows per workspace, including immediate-deletion / zero-retention mode for sensitive workloads.
Railwail does not train models on customer prompts or outputs. We pass requests through to upstream providers and rely on each provider's no-training contractual terms (OpenAI, Anthropic, and others offer this by default for paid API access).
Self-serve data export (Article 15) and account deletion (Article 17) are accessible from the dashboard. Exports include account profile, usage records, billing history, and all stored prompts within the retention window.
Reliability
Uptime & failover
The gateway sits between you and dozens of upstream providers. We treat their failures as our problem â provider-level outages are absorbed by failover routing rather than passed through to the customer.
Live operational status, historical uptime, and incident post-mortems are published at status.railwail.com. Subscribe by email or webhook for incident notifications.
When a model is hosted on more than one provider, the gateway can automatically reroute around an outage at the upstream provider with no SDK change on the customer side. Failover policy is configurable per workspace.
The gateway, control plane, and PostgreSQL are deployed across Hetzner regions with hot-standby replicas. RTO is minutes, RPO is single-digit seconds.
Compliance & security contacts
Reach the right team directly. We acknowledge security and privacy mail within one business day.
For the full text of our privacy notice and cookie usage, see the Privacy Policy and Cookie Policy. Terms of service are here.
Build on EU AI infrastructure
âŹ5 starter credit. No card required. DPA available on request.