Railbase

Das maßgebliche Rechtsdokument ist in englischer Sprache. Navigation und erklärender Site-Inhalt sind lokalisiert.

Previous edition 3.5

Railbase Subscription Agreement

Version: 3.6 Effective date: 8 October 2026

This Railbase Subscription Agreement ("Agreement") is a binding agreement between you ("you", "Customer") and Silkway Tech LLC, a Wyoming limited liability company with a mailing address at 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA ("Company", "we", "us"). It governs each paid Railbase Product you evaluate, subscribe to, install, and use through railbase.app.

This Agreement supplements the Terms of Service (account, ordering, billing, tax, KYC, sanctions, refunds and the railbase.app control plane) and the Railbase EULA (software and company execution rights). By purchasing the Railbase company subscription or accepting an expressly offered evaluation or additional scope, you agree to this Agreement and the applicable Product safeguards and only those conditional industry Schedules applicable under Sections 3 and 15. A Schedule's presence is not an offer of that capability. The stable URL and document identifier plugin-agreement are retained so earlier links and acceptance evidence remain verifiable; renaming this Agreement does not create a new subscription or amend earlier accepted terms.

1. Product model and definitions

The current company Products are Railbase Core, Accounting Suite and GRC Suite. Core is the execution foundation; both Suites run inside Core and require a valid Core entitlement for the same company. Each Suite is a separate Product subscription, not standalone software. Components and Connector have no separate customer price. Future industry solutions are not included or offered by this Agreement.

A Product is the commercial unit identified in the accepted Account offer or Order. Railbase Core is the native-binary foundation for identity, company authority, data, events, documents and supported work processes. Accounting Suite supports financial work; GRC Suite supports governance, risk, compliance, controls and audit. Their respective safeguards are in Schedules B and C.

A Component is a proprietary licensed extension delivered as a signed, encrypted data-resident bundle with backend logic, schema and declared UI. It runs inside Core through mediated platform capabilities, with no standalone executable, process, port, database or supported external run path. It is a delivery and entitlement unit, not a separate customer-facing product or sale unit. The Connector Component is bundled integration capability with no separate price, trial or subscription.

The three current Products have one company tariff and no Basic/Pro/Max commercial variants. Exact capabilities, supported release and any documented capacity are identified in the accepted offer or Order; the absence of plans does not make capacity unlimited. A historical Product Plan identifier may remain in prior Orders or technical entitlement records and retains only its expressly accepted meaning.

Education, Farm, Budget and other future industry Schedules below are conditional safeguards for separately accepted scope. Their presence is not availability, automatic inclusion or a promised release date; no future delivery obligation arises merely from this Agreement.

2. Product subscription license

Subject to your compliance with this Agreement and payment of applicable fees, the Company grants you a non-exclusive, non-transferable, non-sublicensable, revocable license to install and use the subscribed Product through its supported native binary or delivered encrypted Components, inside your own Railbase installation, for your internal business purposes, for the named company, Product Plan, deployment scope, and subscription term recorded at checkout or in an Order.

The Product subscription is bound to the specific named legal company selected in the Customer Account. Human users, job positions, role assignments, approvers, and viewers are authorization concepts, not company subscription pricing units. A Product license does not transfer to another legal entity merely because the same Account manages both entities; a supported reassignment requires the controls and approval stated in the Account or Order.

The Product's versioned composition and fingerprint form part of the entitlement snapshot. Each included Component receives the technical entitlement needed to deliver that Product. The Customer does not acquire source code, ownership of a Component, or a right to use a Component outside an active entitlement source.

3. Ordering and the Account-only purchase boundary

Self-service Product acquisition is available only through a signed-in Railbase Account for a named company whose required company-verification/KYC status is approved and whose transaction clears the Terms' payment, sanctions, export, and tax controls. Public Product pages and a self-hosted Railbase console may describe a Product or link to the Customer Account, but they do not originate or authorize a paid charge.

Each self-service Product subscription creates one Product subscription and one Product line with the payment provider. The Product price is the accepted company Product price; it is not calculated by adding catalogue prices for Components. railbase.app may show a Component breakdown as technical entitlement and accounting detail, including zero-value allocations, without turning a Component into a separately priced SKU.

Checkout blocks a duplicate active subscription for the same Product and named company. A company may subscribe to different Products that contain one or more shared Components. Each Product remains independently priced and billed, and Component overlap does not create a discount, refund, credit, or right to unbundle a Product unless checkout or an Order expressly states otherwise. The control plane retains each Product as a separate entitlement source and composes the effective technical entitlement from all active sources.

Accounting Schedule B applies to Accounting Suite; GRC Schedule C applies to GRC Suite. The other industry Schedules apply only when the corresponding scope is expressly included in an accepted Account offer or Order under Section 15. They do not create a separate Component subscription, SKU, price, agreement or checkbox. The Account presents one affirmative acceptance for this Agreement and the Terms of Service; its evidence pins the exact version and hash of this complete document, including the applicable Schedule. Purchasing Core alone does not purchase or activate either Suite or any future industry solution.

4. Product pricing, revenue evidence, renewal and cancellation

For newly accepted subscriptions, the monthly fee for each Product and each verified company is max(USD 99, 0.5% of monthly company revenue), before applicable taxes. USD 99 is a minimum, not a cap. There are no Basic, Pro or Max commercial plans for Core, Accounting Suite or GRC Suite. People, roles, devices, installed Components and server processes are not separate billing units.

Product fees add together. Core plus Accounting Suite or Core plus GRC Suite starts at USD 198 per company per month; all three start at USD 297. Above USD 19,800 monthly revenue, the charge is 0.5% per Product: two Products total 1% and three total 1.5%. For example, USD 50,000 revenue produces USD 250 per Product, USD 500 for two, or USD 750 for all three, before tax. A Suite subscription does not include the Core fee.

Advance and settlement for the same month. Each Product is billed in two stages: USD 99 in advance, followed by a separate settlement of max(0, rounded 0.5% of that same month's company revenue minus USD 99). The advance is credited once; the settlement does not charge another monthly minimum or renew another service period. A zero difference generates no additional invoice. For USD 50,000 revenue, each Product has a USD 99 advance and USD 151 settlement (USD 250 total); all three have USD 297 in advances and USD 453 settlement (USD 750 total), before tax.

Calendar and first month. The billing month is a UTC calendar month. The first USD 99 advance is due when the Product starts, including a start partway through a month; the minimum is not prorated. Later advances are due at the start of each calendar month. Settlement is calculated at the close of the last calendar day, once that full day's Accounting entries and the monthly ledger period are closed. Processing may occur immediately after the month-end cutoff or later when the authoritative report arrives; we do not guess the final day's revenue or silently use the previous month's revenue for a new month's advance. A valid cancellation ends future advances at the recorded service boundary; the settlement for services already provided remains payable.

Revenue and evidence. Revenue is the authenticated company-scoped USD aggregate reported by the supported Accounting Suite from its closed general-ledger period: credits less debits on accounts classified as income. It is not profit, cash receipts, a website estimate or combined revenue of other companies. You must keep complete, accurate source records and income classification and promptly close the month. We receive the month, USD minor-unit amount and evidence hash, not underlying journals or documents. Negative or zero revenue does not remove the USD 99 minimum. The 0.5% amount is rounded separately per Product to the nearest USD cent, half up. Without subscribed Accounting and without a reported aggregate, the minimum applies. If Accounting was subscribed for the service month but its required report or supported USD amount is missing, the settlement waits for that evidence; the next month's USD 99 advance is independent. No five-day payment countdown starts on an unissued draft or a revenue/tax/compliance hold. Accepted month evidence and finalized invoices are immutable; an error must be resolved through support and a documented correction, never an undisclosed rewrite.

Payment deadline and company suspension. Each payable advance or settlement is due when the invoice is finalized for automatic collection, or on its expressly stated due date. If Stripe has not confirmed payment within five elapsed days (120 hours) after that due time, business access for the affected named company is paused across Core and its Suites, even if another Product's invoice is paid. Payment-in-transit evidence alone does not mark the invoice paid. Other companies remain subject to their own invoices and access conditions. Account access to bills/payment and necessary installation administration remain available; suspension does not delete the native binary, Vault records or backups. Connected installations receive the current signed billing decision through regular checks. A signed company lease is valid for at most 24 hours and is capped at any already-known five-day deadline; offline or onboarding grace does not extend that billing deadline. A prolonged failure to refresh the lease can therefore pause company business access even while payment is being investigated.

Recovery and temporary support access. Normal access can resume after authenticated Stripe confirmation settles all overdue invoices for the company and all other entitlement, identity and compliance conditions are satisfied. Paying one invoice does not clear another unpaid invoice, cancel a refund/revocation or buy a new subscription period. An authorized support operator may grant a documented temporary access extension while a payment is in transit, for a stated reason and expiry of no more than seven days per grant. The extension may be ended earlier, expires automatically and is audited with the operator's identity. It leaves every invoice, debt and actual payment record unchanged and does not override sanctions, identity, revoked licences or other security restrictions. It is discretionary access credit, not a waiver or promise of indefinite operation.

Existing contracts. Accepted historical prices, Orders, invoices and paid periods remain unchanged. A migration to this tariff or a change to the formula requires a prospective offer, applicable notice and acceptance; publication, deployment or a heartbeat is not acceptance. Internal legacy plan identifiers do not create current commercial plans, unlimited capacity or a new customer charge. The accepted Account offer or express Order governs the applicable price and documented capacity.

Each Product's agreed composition is indivisible: an included Component cannot be independently removed, downgraded, cancelled or priced. Different Products may share a Component and remain independently billed. Ending a source removes only that Product's rights; the Component may continue if another active Product supplies it and required Core remains active.

Subscriptions renew on the first day of each UTC calendar month until cancelled. Ordinary cancellation stops the whole Product at the end of its paid term; no credit is owed for unused parts or time except under the Refund Policy or mandatory law. Adding another Product creates its own disclosed monthly subscription; there are no Basic/Pro/Max changes or plan proration under the standard company tariff. Existing expressly accepted historical plan provisions apply only to their own contracts.

A Suite requires Core for the same company. Cancelling Core does not automatically cancel the Suite's separate billing; cancel each subscription you no longer want. Non-payment, full payment reversal, chargeback, breach, sanctions, export controls, account closure or adverse enhanced verification can suspend access earlier under the Terms. Removal does not automatically delete self-hosted records.

5. Technical protection, activation, and revocation

You acknowledge and agree that:

  1. Components are encrypted at rest and license-gated at execution and run only while at least one valid entitlement source for the named company is present;
  2. licenses may be device-bound (node-locked) to the Railbase instance that activates them, and moving them may require release or re-pointing through the Account;
  3. Railbase periodically verifies licence state with railbase.app; a connected instance normally applies a suspension on its next heartbeat, while a node-bound token is a rolling validation lease of no more than 24 hours, capped by the applicable paid term or the limited billing access credit expressly described in Section 4; that credit never extends the paid commercial period;
  4. the Company may suspend or revoke an affected Product or Component entitlement for non-payment, full payment reversal, chargeback, cancellation at the applicable boundary, breach, sanctions/KYC findings, export restrictions, or misuse; a partial credit note alone does not revoke an otherwise paid entitlement; and
  5. attempting to decrypt, extract, copy, study, modify, or run a Component outside the licensed Railbase core, tamper with enforcement, or share licence credentials outside the licensed organization is a material breach.

6. Restrictions

You may not, and may not permit or assist anyone else to: (a) reverse engineer, decompile, disassemble, decrypt, or derive the source or contents of a Component except to the extent the restriction is prohibited by applicable law; (b) modify or create derivative works of a Product or Component; (c) redistribute, resell, sublicense, rent, lease, or host a Product or Component for third parties; (d) exceed the licensed company, Product Plan, deployment, quota, or usage scope; (e) circumvent entitlement, metering, signature, or execution controls; (f) separate and use a Component as though it were independently purchased; or (g) use a Product or Component in violation of applicable law.

7. Evaluation and internal testing

Railbase may be evaluated only under an expressly offered evaluation or internal-testing assignment, after the applicable Account and company-verification gates. Railbase or additional scope has a trial only where the Account or current offer expressly provides one. The public demo at core.railbase.app uses synthetic data and does not grant production hosting or installation rights. Product trials are time-limited, company-specific, may be limited by account, company, deployment, device, or network, and may be revoked at any time. An internal-testing assignment is invitation-only, is not a commercial purchase, and carries no availability or support commitment.

A Component included in a Product does not acquire a standalone trial merely because it can be installed independently by the runtime. Connector has no standalone trial.

8. Data, dependencies, and third-party services

Products run inside Railbase. On-premise business data stays in your Vault; the control plane ordinarily receives limited Account, company, entitlement, deployment, version and heartbeat metadata, plus the authenticated monthly billing aggregate described in Section 4 and the Privacy Policy. In expressly accepted Cloud hosting, the Company additionally processes Hosted Data under the Cloud Schedule and DPA. Materials submitted for support are processed under the DPA.

Components may publish and consume declared events through the Railbase event bus and may use core-mediated integrations. One Component's output does not become warranted, verified, or upgraded in status merely because another Component consumes, displays, attaches, or acts on it. The applicable Suite Schedule continues to govern Product output wherever that output is used. You are responsible for compatible configuration, appropriate roles, lawful source access, cross-Component workflows, and third-party services and credentials you configure.

9. Installation, updates, and compatibility

After purchase, the Product appears as an owned Product in Railbase. Installation is initiated from the self-hosted Railbase administration surface. Before installation, railbase.app verifies the Account entitlement, named company, Product, Product Plan, composition fingerprint, exact release-locked Component set, Component versions, and signed artifacts. Railbase then installs each Component through its ordinary protected installation path.

Product and Component updates are delivered only through the Railbase distribution control plane. An update may require a minimum Core version. The Company may change or retire a Product, Product Plan, or Component prospectively. A retired Product remains licensed for the paid term unless otherwise stated, but may stop receiving updates or new sales. Compatibility with future Core versions is not guaranteed beyond commercially reasonable efforts.

10. Ownership

Products, Components, bundles, manifests, documentation, trademarks, and related intellectual property are and remain the exclusive property of the Company and its licensors. They are licensed, not sold. All rights not expressly granted are reserved.

11. Warranty disclaimer

PRODUCTS AND COMPONENTS ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. PRODUCT OR COMPONENT OUTPUT — INCLUDING MACHINE TRANSLATION, ANALYTICS, RISK, COMPLIANCE, CONNECTOR, FINANCIAL, EDUCATION, OR AUDIT CONTENT — IS PROVIDED FOR CUSTOMER EVALUATION AND IS NOT PROFESSIONAL, LEGAL, FINANCIAL, ACCOUNTING, EDUCATIONAL, REGULATORY, OR AUDIT ADVICE. THE APPLICABLE SUITE SCHEDULES STATE ADDITIONAL LIMITATIONS AND OPERATIONAL SAFEGUARDS.

12. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE COMPANY WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, ARISING FROM OR RELATED TO A PRODUCT OR COMPONENT. THE COMPANY'S TOTAL AGGREGATE LIABILITY UNDER THIS AGREEMENT WILL NOT EXCEED THE AMOUNTS YOU PAID FOR THE PRODUCT GIVING RISE TO THE CLAIM IN THE 12 MONTHS BEFORE THE CLAIM. MANDATORY LAW MAY LIMIT THE APPLICATION OF THIS SECTION.

13. Term and termination

This Agreement applies while you hold a Product subscription, Product trial, or internal-testing assignment. Either party may terminate for the other's material breach not cured within 30 days after notice, except that a breach of Sections 5–6 or a legally required suspension may be acted on immediately.

When a Product or entitlement source ends, affected Components stop executing when no other active source supplies them. Historical records remain in the Customer's Vault under the Customer's retention policy and may become available again after a later compatible subscription. The Customer must export or delete that data through Railbase; the Company cannot do so from railbase.app.

14. Governing law; changes; general

This Agreement is governed by the laws of the State of Wyoming, USA, without regard to conflict-of-laws rules; exclusive venue lies in the state or federal courts located in Wyoming. If any provision is unenforceable, the remainder stays in effect.

The Company may update this Agreement prospectively, including its Suite Schedules. The exact version and hash accepted at checkout are retained as evidence. The accepted version governs that acquisition unless a later version is validly accepted or applicable law requires otherwise. Material changes intended to apply to a later renewal will be notified before that renewal where required.

15. Suite Schedule framework

Schedules B and C govern the current Accounting Suite and GRC Suite respectively. The remaining Schedules are conditional industry safeguards, not current product offers; they apply only to corresponding scope expressly included in an accepted Account offer or Order, including a historical offer where applicable. Their presence does not make a future industry solution available, include it in Core or either Suite, or promise a delivery date. When the relevant scope is expressly included, the same safeguards apply to every applicable plan without a second agreement or acceptance. Obligations for retained data, exports, downstream copies, decisions, investigations, educational or financial records, evidence and reports survive as stated after suspension, plan change, expiration or termination.

For every Suite Schedule:

  1. "Source Data" means data, documents, credentials, records, classifications, mappings, instructions, and other inputs supplied or made accessible by the Customer or its systems;
  2. "Product Output" means results, indicators, scores, mappings, alerts, findings, recommendations, transformed data, calculations, reports, logs, and other material produced or displayed by the Suite;
  3. "Human Review" means documented review by a competent and authorized person who can inspect relevant Source Data, understand disclosed limitations, seek additional evidence, disregard or override Product Output, and accept responsibility for the resulting action;
  4. "Material or Adverse Decision" means a decision materially affecting a person or organization, including education, employment, payment, credit, benefits, discipline, investigation, reporting, contractual rights, or another significant opportunity or burden; and
  5. the Customer is the controller and operator of its self-hosted environment and remains responsible for lawful authority, notices, permissions, data quality, configuration, roles, segregation of duties, retention, exports, backups, incident response, regulatory assessment, and decisions made from Product Output.

Connector is included integration fabric, not a separate customer-facing product, system of record, backup, archival service, or guarantee of semantic correctness or downstream processing. For every Suite, the Customer must have lawful authority to access each source and destination; comply with third-party terms; use dedicated least-privilege credentials and read-only access where feasible; validate extraction scope, identifiers, mappings, units, currencies, time zones, transformations, deduplication, ordering, reference data, and recipients; reconcile material counts and totals; protect credentials and exports; control event subscriptions, replay, retention, correction, and deletion of downstream copies; and revalidate integrations after source, schema, permission, or Product changes. Successful transfer proves only the recorded technical operation.

No Suite Schedule makes the Company the Customer's educator, school operator, employer, accountant, tax adviser, auditor, lawyer, compliance officer, data controller, fiduciary, system of record, or decision maker. Use of AI-assisted development tools by the Company does not transmit Customer business data to a third-party AI service unless an expressly documented Product feature does so and does not reduce the Customer's validation, Human Review, monitoring, or legal obligations.

Schedule A — Education Suite

A.1 Intended purpose and institutional responsibility

Education Suite supports admissions, academic delivery, school administration, learner and parent services, receivables and ledger operations and library, procurement, workforce, payroll, digital learning, payables, budgeting, and treasury workflows. It does not confer accreditation, authorize the Customer to operate an educational institution, determine the curriculum required by law, guarantee learning outcomes, attendance, progression, safeguarding, funding, payment, or regulatory compliance, or replace qualified educational, safeguarding, legal, accounting, or employment judgment.

The Customer remains solely responsible for institutional authorization; admissions criteria; curriculum and assessment policy; academic records; grading, progression, discipline, accommodations, safeguarding, mandatory reporting, and communications; the identity and authority of learners, parents, guardians, employees, contractors, and applicants; and every Material or Adverse Decision. Product Output must not be the sole or determinative basis for admission, exclusion, grading, discipline, special-support placement, employment, compensation, or another Material or Adverse Decision.

A.2 Learners, minors, privacy, and records

The Customer must determine and document the lawful basis for processing learner, child, parent, guardian, applicant, workforce, library, attendance, assessment, financial, and support data; provide required notices and obtain required consents or authorizations; verify guardian and representative authority; restrict access by role and need; apply age-appropriate and safeguarding controls; honor applicable access, correction, objection, export, retention, and deletion rights; and prevent disclosure between unrelated households, learners, classes, or companies.

Education Suite is not the Customer's exclusive archive. The Customer must maintain authoritative academic, attendance, assessment, safeguarding, employment, payroll, accounting, and statutory records for the periods and formats required by law, reconcile imports and migrations, and preserve a reproducible history of material changes, approvals, overrides, and communications.

A.3 Safeguards for every Product Plan

On every Product Plan, the Customer must validate admission-to-receivable, learner charge, cash, journal, migration, academic calendar, enrollment, class, attendance, assessment, and guardian workflows before production use. The Customer must also control library patron privacy, fines, procurement authority, supplier records, employment status, payroll inputs, transport access, and incompatible workforce duties. The Customer must also validate learning content and accessibility, assessment configuration, digital-learning completion, budget authority, commitments, payables, payment approvals, and treasury release controls.

No migration count, successful import, generated balance, completion marker, attendance state, grade, recommendation, or workflow approval proves that the underlying record is complete, lawful, pedagogically appropriate, or correct. The Customer must test representative and edge-case data, reconcile material populations and totals, monitor errors and access, and suspend affected use when integrity, privacy, or safety is in doubt.

Schedule B — Accounting Suite

B.1 No accounting, tax, banking, or assurance service

Accounting Suite supports ledgers, payables, receivables, tax evidence, treasury, bank reconciliation and fixed assets and budgeting. It does not provide accounting, tax, legal, investment, banking, audit, or assurance services; determine the accounting framework or tax treatment applicable to the Customer; guarantee that books close, statements are fairly presented, returns are correct, payments settle, assets exist, controls are effective, or records satisfy a regulator, auditor, lender, or investor; or replace appropriately qualified professionals.

The Customer remains solely responsible for its chart of accounts, opening balances, policies, periods, currencies, exchange rates, dimensions, counterparties, tax codes, source documents, recognition, classification, estimates, accruals, allocations, consolidations, eliminations, close, financial statements, filings, books and records, approvals, payment instructions, and compliance with accounting, tax, banking, corporate, employment, and record-retention requirements.

B.2 Completeness, reconciliation, and authoritative records

The Customer must identify complete relevant populations, reconcile subledgers and imported data to authoritative sources, investigate duplicates and gaps, validate journal balance and posting dates, preserve source documents and approval evidence, control period open and close, and maintain an independent backup and recovery path. A successful migration, balanced journal, zero, empty report, absent record, generated reconciliation, calculation, tax result, budget variance, or completed workflow does not establish completeness, accuracy, authorization, recoverability, or compliance.

Before production use and after material change, the Customer must test known-answer, boundary, duplicate, incomplete, reversal, multi-currency, tax, period-close, failure, retry, and recovery scenarios; validate mappings, calculations, permissions, event subscriptions, exports, and interfaces; document acceptance criteria and limitations; and obtain appropriate finance approval.

B.3 Payments, tax, assets, and budgets

The Customer must apply segregation of duties and approval limits to vendor setup, invoice entry, journals, bank details, payment preparation, approval, release, refunds, write-offs, tax configuration, asset capitalization and disposal, and budget changes. Treasury or payment Product Output is an instruction or workflow state, not confirmation from a bank or beneficiary; the Customer must independently verify material payment details and settlement and promptly contain suspected fraud or credential compromise.

Tax calculations and evidence depend on Customer configuration and Source Data and are not tax advice or a filed return. Fixed-asset records do not establish legal title, existence, condition, impairment, valuation, or tax basis. Budgets, forecasts, commitments, and variances are management tools, not guarantees of availability, performance, solvency, or future results. Qualified Human Review remains required for material postings, filings, payments, estimates, asset actions, close decisions, and external reporting.

Schedule C — GRC Suite

C.1 Analytical status and required Human Review

GRC Suite supports enterprise risk, obligations, policies, controls, evidence, concerns, screening, cases, issues, remediation, audit analytics and internal-control assessment under the current GRC Suite subscription. Product Output is an analytical indication, not a verified fact, proof of wrongdoing, legal or regulatory conclusion, official screening decision, compliance certification, risk guarantee, control attestation, audit opinion, assurance conclusion, or substitute for an investigation or professional judgment. It may be incomplete, stale, ambiguous, false-positive, or false-negative and does not change status when scored, summarized, exported, sent through the event bus, or attached to another record.

Before reliance, the Customer must establish a lawful purpose and processing basis; validate Source Data, populations, rules, thresholds, watchlists, mappings, roles, jurisdictions, workflows, and recipients; document intended use, foreseeable misuse, affected groups, impact, error tolerance, escalation, override, contest, and remediation; apply qualified Human Review before every Material or Adverse Decision; independently corroborate allegations, sanctions, legal, regulatory, audit, control, and enforcement conclusions with authoritative evidence and qualified professionals; and preserve the reviewer, evidence, reasoning, overrides, and final decision.

The Customer must not use Product Output as the sole or determinative basis for a Material or Adverse Decision; represent it as proof, certification, opinion, attestation, legal conclusion, verified allegation, or Company endorsement; use it for unlawful discrimination, social scoring, covert surveillance, prohibited protected-characteristic inference, manipulation, retaliation, or punishment; or deploy it in a prohibited or high-risk context without required assessment, oversight, registration, authorization, and affected-person process.

C.2 Risk, compliance, concerns, and case management

For every GRC Suite subscription, the Customer remains responsible for its risk methodology, appetite, taxonomy, ownership, ratings, obligations, policies, control mapping, screening scope, investigation protocol, issue severity, remediation, certification, and regulatory reporting. Concerns and speak-up records may be highly sensitive: the Customer must restrict identity and case access, protect confidentiality and lawful anonymity, prevent retaliation, manage conflicts, preserve evidence, provide required notices and response rights, and meet non-waivable reporting and investigation duties.

No score, match, flag, control status, policy acknowledgment, case state, issue, remediation state, or certification establishes that risk is acceptable, compliance has been achieved, a person committed misconduct, or a control operated effectively. The Customer must monitor drift, bias, false positives, false negatives, complaints, overrides, access, and incidents and suspend or constrain affected use where integrity, rights, confidentiality, or safety is in doubt.

C.3 Audit analytics — every GRC Suite subscription

Audit is included in GRC Suite. The Suite does not perform an audit, review, agreed-upon procedures engagement, attestation, certification, or other assurance engagement under ISA, GAAS, PCAOB, IIA, or another professional framework. The Company is not the Customer's auditor and assumes no auditor independence, skepticism, evidence, documentation, reporting, or professional duty. The Customer remains responsible for engagement acceptance, competence, planning, complete populations, scope, sampling, materiality, tolerable error, assertions, procedure design, sufficient appropriate evidence, findings, communications, reporting, and remediation.

A zero, empty result, inaccessible field, unsupported format, timeout, refusal, successful run, reconciliation, ratio, trend, journal-entry candidate, or recommendation does not establish completeness, absence of fraud or error, or a required conclusion. A finding requires competent review of relevant and contrary evidence, documented criteria and assertion, and an authorized conclusion. Before an allegation, external report, disciplinary action, control conclusion, or other Material or Adverse Decision, the Customer must independently corroborate the matter and provide any process and opportunity to respond required by law or policy.

C.4 Internal controls — every GRC Suite subscription

Internal-control management is included in GRC Suite. The Customer remains responsible for control objectives, design, ownership, frequency, evidence standards, tester competence and independence, sample selection, exceptions, deficiency classification, aggregation, remediation, management attestation, and external reporting. A configured control, uploaded evidence, completed test, automated signal, workflow approval, or management attestation does not by itself prove design adequacy or operating effectiveness.

The Customer must test representative, boundary, incomplete, duplicate, manipulated, known-answer, access, failure, and recovery scenarios before production reliance and after material change; protect evidence and exports; segregate incompatible duties; preserve reproducible records; and promptly contain and investigate material security, integrity, confidentiality, or decision-quality incidents.

Schedule D — Farm Suite

D.1 Intended purpose and operating responsibility

Farm Suite supports planning, execution, animal and crop care, inventory, quality, maintenance, traceability and operational evidence for the Activity Profiles expressly certified in the purchased release. An Activity Profile is a versioned operating configuration inside the Product, not a separate Product, plan or price. A profile described as planned, discovery or unavailable is not part of the supported commercial scope until a later signed Product release admits it.

The Suite does not provide agronomic, veterinary, food-safety, environmental, engineering, legal or regulatory advice; guarantee yield, health, welfare, quality, traceability, resource availability or commercial results; certify a farm, product, treatment, withdrawal, movement, permit, filing or report; or replace appropriately qualified professionals and authorized public bodies. The Customer remains responsible for facilities, animals, crops, people, equipment, inputs, labels, prescriptions, biosecurity, welfare, food safety, water and land rights, environmental limits, emergency response and every physical or regulated action.

D.2 Global baseline and country overlays

The global operating baseline records non-regulated work, evidence, correction, segregation-of-duties and traceability invariants. It does not assert that one country's permits, labels, withdrawal periods, reporting formats, movement rules, veterinary authority, pesticide rules, water limits, welfare standards or retention periods apply elsewhere. A regulated action must remain unavailable unless the Customer has installed and selected a signed Product overlay applicable to the operating country, activity, species/crop and period.

The Customer must determine applicable law and competent authority, obtain and maintain permits and professional authorizations, validate Product policy sets against authoritative sources, keep jurisdiction and operating location current, and suspend affected use when applicability, evidence or authority is uncertain. A completed Workflow, green status, generated certificate, absence of an alert or successful event delivery does not establish legal permission or regulatory compliance.

D.3 Human review, AI assistance and physical execution

AI Agent Profiles in Farm Suite are supporting assistants only. They may help summarize Product records or prepare suggestions when a separately signed model, knowledge and verifier pack is enabled, but they have no business authority and must not approve, prescribe, apply, release, submit, post, certify or execute an operation. The Customer must ensure competent Human Review of AI output and must not treat it as a diagnosis, prescription, agronomic direction, safety clearance, quality disposition or regulatory decision.

The Customer must verify identity, object scope, current conditions, source data, units, dates, evidence, equipment availability, medicine/input status, withdrawal and quarantine restrictions and required independent approvals before physical execution. The Customer must reconcile actual field, herd, flock, greenhouse, inventory, laboratory, maintenance and traceability outcomes back to the Suite, preserve corrections and exceptions, and operate independent backup, recovery, incident and business-continuity procedures.

D.4 Plans and capacity

Basic, Pro and Max contain the same certified roles, workflows, components and supported Activity Profiles. The plans differ only by the numeric production- period admissions stated at checkout. A quota does not change legal scope, professional responsibility, country applicability, safety controls or the required evidence and Human Review. Idempotent retry of an admitted operation does not consume a second admission; exceeding a quota does not authorize a side-channel process or removal of controls.

Schedule E — Budget Suite

E.1 Intended purpose and operating responsibility

Budget Suite supports governed budgeting for either a family office or a legal company: effective-dated budget articles and period limits, spending requests, expense facts, transfers, rollups derived from released lines, article-to-ledger mappings and retained payment and export evidence, through the Core Workflows the purchased release admits. A profile, budget article, mapping or rollup is a configuration and record inside the Product, not a separate Product, plan or price.

The Suite does not provide financial, investment, tax, credit, insurance, legal or regulatory advice; guarantee savings, solvency, creditworthiness or any financial outcome; execute, guarantee or reverse a payment or transfer at a bank or payment provider; or replace appropriately qualified professionals and authorized institutions. The Customer remains responsible for the accounts, balances, payments, obligations, tax positions, filings and every financial decision recorded or supported in the Product.

E.2 Global baseline and country overlays

The global operating baseline records non-regulated request, evidence, correction, segregation-of-duties and traceability invariants for budget operations. It does not assert that one country's tax treatment, reporting format, consumer-credit, payment or retention rules apply elsewhere. A regulated action must remain unavailable unless the Customer has installed and selected a signed Product overlay applicable to the operating country and period.

The Customer must determine applicable law, validate Product policy sets against authoritative sources, keep jurisdiction and operating-profile context current, and suspend affected use when applicability, evidence or authority is uncertain. A completed Workflow, green status, exported statement, absence of an alert or successful event delivery does not establish a tax position, legal permission or regulatory compliance.

E.3 Human review, AI assistance and execution

AI Agent Profiles in Budget Suite are supporting assistants only. They may help summarize Product records or prepare suggestions when a separately signed model, knowledge and verifier pack is enabled, but they have no financial authority and must not approve, pay, transfer, post, file or execute an operation. The Customer must ensure competent Human Review of AI output and must not treat it as financial, tax or legal advice. Every payment, transfer or filing is performed by the Customer through the Customer's own institutions and channels; the Product records the decision and retains the evidence.

16. Railbase company Product, capacity and optional capabilities

The current Products and tariff are defined in Sections 1 and 4. Industry solutions remain future scope. Users, roles, devices and server processes do not independently create company subscription charges.

Each documented capacity grant identifies its counting event and period. Monthly billing does not imply a monthly reset of an annual quota. Exhaustion restricts new counted work rather than removing capabilities or cancelling already admitted work. Expiry, revocation and security suspension follow their separate execution gates; removing commercial tiers does not rewrite accepted historical capacity.

AI, Mobile and distributed capabilities require supported releases, permissions and applicable policy/readiness prerequisites. Implemented code or a Suite lock alone does not warrant every optional capability at a particular installation. External AI usage, server operations, migration, integration, training and premium support are excluded unless expressly included.

A workflow recommendation or completion marker is not a committed downstream business effect unless that effect is recorded. Applied effects may require a linked compensating process. Removal and suspension do not erase retained records; access, export and recovery require supported interfaces, compatible software and valid authority. No perpetual unrestricted execution or export entitlement is promised.

17. Contact

Silkway Tech LLC — 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA. Questions: via the support page.

Expressly accepted Cloud hosting

The Cloud Schedule hosts the same Core and subscribed Suite functionality; it does not combine their separate Product fees. Statements in this document about customer-operated or on-premise infrastructure apply to that deployment mode. For a company expressly offered and enrolled in Company-managed hosting, the Cloud Service Schedule and DPA additionally govern hosting, included capacity, operational responsibility, service activation, data return and deletion. Cloud hosting is not made generally available by this publication; the public synthetic demo remains separate. No existing accepted Order, invoice or acceptance record is rewritten. Where the Cloud Schedule expressly provides a remedy for failed initial Cloud delivery, that specific remedy applies.