# Security model

> Private storage, signed delivery, tenant isolation and governed administration.

_Updated: 2026-09-22_

Railbase uses separate encrypted company Vaults and a System Vault for shared
identity and authority. On-premise, the customer operates the hosting boundary.
In Managed Cloud, Railbase operates a shared process under the Cloud Schedule
and DPA. Separate files and keys do not mean separate virtual machines or
operating-system processes.

## Core controls

- independently generated company encryption keys and protected installation unlock material;
- tenant-scoped data access and role-based authorisation;
- one human identity with separate installation and company authority;
- signed releases and hash verification;
- fail-closed entitlement at execution;
- audit events for sensitive administration and business actions;
- encrypted file storage when enabled by the operator;
- controlled backup, restore and update procedures;
- human approval policy for high-impact AI actions;
- signed federation pairing between approved estates, only after activation.

## Customer duties

The on-premise operator must protect secrets, restrict administrator surfaces,
configure TLS/network controls, maintain least privilege, operate backups and
promptly apply supported security updates. Managed infrastructure duties follow
the Cloud Schedule; customers still control membership and company permissions. These duties can be assigned to an
implementation partner but remain part of the customer's operating model.

## Reporting

Report a suspected vulnerability through the contact in
`/.well-known/security.txt`. Do not include live customer data in an initial
report. Silkway Tech triages reports under its vulnerability-management and
incident-response procedures.
