Security model
Private storage, signed delivery, tenant isolation and governed administration.
Updated
Railbase uses a private-estate security model: ordinary business data remains under the customer's hosting boundary, while railbase.app controls identity of the buyer, entitlement and signed distribution.
Core controls
- per-estate private Vault secret;
- tenant-scoped data access and role-based authorisation;
- separate administrator and ordinary-user sessions;
- signed releases and hash verification;
- fail-closed entitlement at execution;
- audit events for sensitive administration and business actions;
- encrypted file storage when enabled by the operator;
- controlled backup, restore and update procedures;
- human approval policy for high-impact AI actions;
- signed federation pairing between approved estates.
Customer duties
The customer must protect secrets, restrict administrator surfaces, configure TLS/network controls, maintain least privilege, operate backups and promptly apply supported security updates. These duties can be assigned to an implementation partner but remain part of the customer's operating model.
Reporting
Report a suspected vulnerability through the contact in
/.well-known/security.txt. Do not include live customer data in an initial
report. Silkway Tech triages reports under its vulnerability-management and
incident-response procedures.