Railbase

权限法律文件为英文。导航和解释性网站内容已本地化。

Archived edition. This is not the current offer; it remains available to verify earlier agreements. Current edition

Terms of Service

Version: 3.5 Effective date: 7 October 2026

These Terms of Service ("Terms") are a binding agreement between you ("you", "Customer") and Silkway Tech LLC, a Wyoming limited liability company with a mailing address at 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA ("Company", "we", "us"), governing your access to and use of Railbase Core, Accounting Suite and GRC Suite, their included modules, licence keys, documentation, downloads, support, billing, and the website and control plane at railbase.app (together, the "Service").

By creating an account, purchasing or trialing an expressly offered Product, downloading the software, installing or using a Product or Component, using a licence key, or otherwise using the Service, you agree to these Terms. If you use the Service on behalf of an organization, you represent that you are authorized to bind that organization, and "you" refers to that organization.

1. The Service

The current company Products are Railbase Core, Accounting Suite and GRC Suite. Core is the execution foundation; both Suites run inside Core and require a valid Core entitlement for the same company. Each Suite is a separate Product subscription, not standalone software. Components and Connector have no separate customer price. Future industry solutions are not included or offered by this Agreement.

Railbase connects company work, documents, human approvals, accounting and controls. The Core is proprietary compiled server software; Suite functionality is delivered as protected Components. Railbase is not an SDK, BaaS, scaffolder or customer software-development platform. Workflow Studio permits supported process configuration within the EULA.

On-premise deployment runs on infrastructure the Customer owns or controls, including its private cloud. You operate and secure that environment and its backups. Company-managed Cloud hosting is available only where expressly offered and accepted under the Cloud Service Schedule and DPA. The synthetic public demo at core.railbase.app is for evaluation, not a hosted production subscription or installation entitlement.

Railbase Mobile is distributed for iPhone through the App Store and for Android through Google Play. It is a client of a supported licensed company workspace, not a separate Product subscription or a grant of server access. Store availability can vary by country and release; supported features depend on the server release, company permissions and Product entitlement.

Railbase does not determine your legal authority, replace required human decisions or certify compliance. You remain responsible for lawful policies, delegations, permissions, source records and configured downstream actions. AI prepares permitted context; required human approval is not replaced by model output.

2. Accounts and eligibility

You must provide accurate account, billing, company, and tax information and keep your credentials secure. An account may contain multiple users and multiple companies. Roles determine which functions a user may perform, and company scopes determine which registered companies that user may see or manage. An invitation grants no access until the invited address accepts it. You are responsible for assigning and reviewing roles and scopes and for all activity under your account, deployments, API tokens, license credentials, and admin users. You must be at least 18 or the age of majority in your jurisdiction and legally able to enter into contracts. You may not use the Service if you are barred from doing so under applicable law.

The human owner role may be transferred only by the current owner to an accepted account member after recent authentication. The account's stable billing/project identifier does not change on transfer. The former owner becomes an administrator unless later removed. You must keep at least one authorized owner and notify us promptly of unauthorized access.

Business use only. The Service, including Railbase Core, downloads, updates, Account, paid Product Plans, Products, and Components, is offered only to businesses and organizations, not to consumers or for personal use. Every paid Product entitlement is issued to a named company or organization (a "tenant" in the software). By creating or using an Account, downloading Core, starting an expressly offered Product trial, or purchasing, you represent that you act in the course of a trade, business, craft, or profession, that you are authorized to act for the relevant organization and named company, and that you are not acting as a consumer. To the extent permitted by law, consumer-protection rights that apply only to consumer contracts — including statutory withdrawal or "cooling-off" rights — do not apply under these Terms.

Core distribution is authenticated and company-gated. Core distribution does not itself grant paid company execution rights and is not anonymous. The download page, installers, raw Core artifacts, checksums, re-downloads, and machine update grants are available only through an authenticated B2B Account with at least one registered company whose effective KYC/company-verification status is approved. A missing company registration, pending or blocked review, blocked or closed Account, or revoked machine credential prevents distribution. The company-verification decision itself fails closed whenever a current sanctions screen is required and the screening snapshot is missing, inactive, or stale. If the enhanced KYB/KYC control described in Section 6 is enabled, distribution also requires its approval for the company's current legal identity and fails closed if that provider control is unavailable. A previously downloaded Core binary may continue running on your infrastructure; blocking distribution does not remotely delete or disable that binary or delete your Vault data, while separately licensed Product and Component entitlements remain subject to their execution-time licence controls.

3. License grant

Subject to your compliance with these Terms, the Railbase EULA, the Railbase Subscription Agreement including the automatically applicable Suite Schedule, and payment of applicable fees, the Company grants you a non-exclusive, non-transferable, non-sublicensable, revocable license to install and use the purchased Product through its delivered Components for the named company, Product Plan, quotas or limits, composition, deployment scope, and term shown in the Order or Account checkout.

You may not: (a) redistribute, resell, sublicense, rent, lease, or host the Software, Product, or Component for third parties except as expressly permitted; (b) remove, bypass, or tamper with licence keys, activation checks, company/Product Plan limits, signatures, or technical protection measures; (c) reverse engineer, decompile, decrypt, or disassemble any object-code or encrypted Component except to the extent this restriction is prohibited by applicable law; (d) use the Service to build a competing distribution or marketplace; (e) share licence keys outside your licensed organization or exceed the licensed company, Product Plan, deployment, quota, or usage scope; (f) separate an included Component and use it as though independently purchased; or (g) use trial, internal, or allowlisted builds outside their intended scope.

Open-source components, if any, are licensed under their own terms, which control for those components.

4. Orders, Product pricing, and billing

For newly accepted subscriptions, the monthly fee for each Product and each verified company is max(USD 99, 0.5% of monthly company revenue), before applicable taxes. USD 99 is a minimum, not a cap. There are no Basic, Pro or Max commercial plans for Core, Accounting Suite or GRC Suite. People, roles, devices, installed Components and server processes are not separate billing units.

Product fees add together. Core plus Accounting Suite or Core plus GRC Suite starts at USD 198 per company per month; all three start at USD 297. Above USD 19,800 monthly revenue, the charge is 0.5% per Product: two Products total 1% and three total 1.5%. For example, USD 50,000 revenue produces USD 250 per Product, USD 500 for two, or USD 750 for all three, before tax. A Suite subscription does not include the Core fee.

Revenue and evidence. The standard tariff uses the previous completed calendar month in UTC, independently of the subscription's renewal day. Revenue is the authenticated company-scoped USD aggregate reported by the supported Accounting Suite from its closed general-ledger period: credits less debits on accounts classified as income. It is not profit, cash receipts, a website estimate or combined revenue of other companies. The Customer is responsible for accurate, complete source records, income classification and closing the period. The control plane receives the month, USD minor-unit amount and evidence hash, not the underlying journals, documents or employee/customer details. Negative or zero revenue does not remove the USD 99 minimum. Each Product amount is rounded separately to the nearest USD cent, half up.

The initial payment uses the minimum when no completed report is available. Without an Accounting subscription and without a reported aggregate, the minimum applies. If Accounting is subscribed but its required report is missing at renewal, the invoice is held for resolution rather than using an unverified amount. A missing or unsupported USD report must be resolved before percentage billing; we do not silently guess currency conversion. The amount and available revenue evidence are shown in the Account before purchase. If that evidence changes before confirmation, a refreshed quote must be confirmed. A renewal uses the accepted formula and its applicable monthly evidence; this is not a new arbitrary tariff.

Existing contracts. Accepted historical prices, Orders, invoices and paid periods remain unchanged. A migration to this tariff or a change to the formula requires a prospective offer, applicable notice and acceptance; publication, deployment or a heartbeat is not acceptance. Internal legacy plan identifiers do not create current commercial plans, unlimited capacity or a new customer charge. The accepted Account offer or express Order governs the applicable price and documented capacity.

Ordering and renewal. A paid self-service purchase starts only in the authenticated Account after the named company's required verification approval. Each Product is one subscription with one Product line, quantity one, in Stripe or the payment provider identified at checkout. The Product price is not a sum of Component prices. Internal Component allocations do not represent separate sales. By purchasing you authorize monthly recurring charges under the accepted tariff, until cancellation. Subscribing to an additional Product starts its own disclosed monthly subscription; the standard company tariff does not use plan upgrades, downgrades or prorated plan changes.

Checkout refuses a duplicate active subscription for the same Product and company. Shared Components retain independent Product entitlement sources; overlap does not create a discount or a right to unbundle a Product. Core is required to execute either Suite; cancelling Core does not automatically cancel separately billed Suite subscriptions. Review and cancel every unwanted subscription in the Account before its next renewal.

Ordinary cancellation stops future renewal at the end of the current paid period. Unpaid invoices may lead to dunning and suspension of the affected Product. Full reversal, chargeback, account closure or a compliance decision may end access earlier under the applicable agreement. Self-hosted data is not deleted by entitlement removal; a later compatible subscription restores rights prospectively and does not recreate deleted data.

Stripe invoices and credit notes are the payment-provider documents of record. We retain immutable Product-level invoice, accepted quote and evidence snapshots. A partial refund alone does not change entitlement; a voided credit note is a reversing adjustment, not deletion of history. Corrections after a finalized period require a documented adjustment, not silent recalculation of its invoice.

After purchase, installation follows the authenticated control-plane lifecycle, with the named company, exact Product composition, release-locked Components, versions and signed artifacts verified. An entitlement cannot be moved to another legal entity except through an expressly supported reassignment.

5. Taxes

Prices are exclusive of taxes unless stated. We use Stripe Tax to calculate applicable sales tax, VAT, GST, or similar transaction tax based on product tax treatment, our registrations, the buyer's location and status, and information supplied at checkout. We may require billing address, country, company legal name, VAT/GST/tax ID, or similar information to calculate tax and issue invoices and credit notes. Tax collected is shown separately from net product consideration and is not treated as our revenue.

You are responsible for any taxes arising from your purchase except taxes on the Company's net income. If you purchase as a business and provide a valid tax ID, a reverse-charge or exemption mechanism may apply where legally available. You are responsible for the accuracy of tax information you provide.

We remain responsible for deciding where we must register, file, and remit; Stripe Tax is a calculation and reporting service and not our or your legal or tax adviser. We may restrict sales in countries or regions where we are not registered, ready, or permitted to sell or where reliable tax treatment cannot be established. A tax ID's acceptance or format validation is not a representation that it belongs to the named company or establishes exemption eligibility.

6. KYC, sanctions, export, and restricted sales

The Service may be subject to U.S. and other export controls, sanctions, and restricted-party rules. You represent that you and your organization are not located in, organized under, ordinarily resident in, or a national of a comprehensively sanctioned country or region; are not on any restricted-party list; and will not export, re-export, provide, or use the Service in violation of applicable law.

Tax availability is not export authorization. Our country list for tax and commercial readiness is independent from the non-optional export-control policy. The latter applies even where checkout can calculate tax. Under the policy effective on the date of these Terms, we do not supply Core, Products, or Components to Belarus, Cuba, Iran, North Korea, Russia, or Syria, or to Crimea/Sevastopol or the controlled Donetsk, Luhansk, Kherson, and Zaporizhzhia regions. We may change, narrow, or expand that list where law, licence conditions, product classification, territorial control, or official guidance changes. A prior download, purchase, or renewal is not a promise that a later operation remains eligible. Selective sanctions applicable to a country are assessed through restricted-party/company screening and do not by themselves mean every person in that country is prohibited.

This destination policy applies to Core downloads, re-downloads, installers, artifacts and machine updates; Product trials and purchases; automatic renewals and reactivations; Product Plan upgrades and downgrades; owned-Product installation; and initial or repeated Component bundle grants. A prohibited registered-company, payer-address, or verified network destination is refused. Country is mandatory for registered companies; where the policy distinguishes prohibited territories inside a country, the company's registered state/province/region is also mandatory and a country-only record is held. We preserve the payer country and region supplied through Stripe so an unattended renewal can be checked before collection. A renewal or proration that fails is held in draft where the payment flow permits and does not receive a new paid-period entitlement.

The optional request-network layer is off by default and does not disable the permanent country/territory policy. When enabled, unavailable network verification fails closed; a prohibited location, Tor, or open proxy is denied; and a browser VPN, private relay, hosting network, or conflict between network and the declared company/payer countries is held for retry without anonymisation or support review. Hosting/VPN is not by itself disqualifying for a self-hosted server update or bundle request, but destination, Tor, and open-proxy denials still apply. You must not use a VPN, proxy, relay, false address, intermediary, affiliate, subsidiary, or other means to evade these controls and must notify us if the intended destination, end user, ownership, or end use changes materially.

Railbase Core is downloadable object-code enterprise-management software with encryption. Pending completion of the applicable U.S. encryption classification/review and reporting process, we operate conservatively under ECCN 5D002 and do not represent Core as EAR99. Potential 5D992.c mass-market treatment is conditional on satisfying the applicable ENC requirements. Signed, encrypted Component bundles have no supported standalone execution path and inherit the Core export review rather than being treated as unrelated data files. These statements describe our present operating posture and are not a customer export-classification ruling or legal advice.

We may screen buyers and active subscribers using names, company names, tax IDs, countries, and other billing information. We may block a purchase, request additional information, cancel a subscription, revoke a license, suspend access, or hold funds where we believe doing so is required or appropriate for sanctions, export, fraud, chargeback, or compliance reasons. If refunding funds would violate or risk violating law, we may hold rather than refund them.

Funds received before a sanctions or export hit. If payment completed before a later screening or destination decision, we suspend the affected server-side access in the same request or screening sweep that detects the hit and stop future renewal as described below, but do not automatically refund, credit, release, transfer, or treat the receipt as ordinary available revenue. We open a restricted-funds case, preserve the payment and screening evidence, classify the event as blocked property, a rejected transaction, no blocking interest/false positive, or another legally supported disposition, contact Stripe where its payment rail is involved, and assess reporting to OFAC and any other authority with jurisdiction. Pending that decision, the amount is tracked as a restricted-funds liability with the tax component separately preserved. A blocked-property amount is not returned to the payer or redirected to another person unless a general or specific licence, regulator order, or other applicable legal authorization permits that movement. A refund is submitted only to the original payment method after the case records a documented no-blocking-interest determination or the required legal authorization. Stripe's own restriction or report does not replace our reporting obligation. We may withhold details from a notice where disclosure is restricted by law.

For a U.S.-nexus case, our internal deadline is no later than ten weekdays after the event for the initial blocked-property or rejected-transaction reporting decision; applicable law and authority instructions control the actual form and deadline. Where reporting is required, the case records the authority, report type, filing reference, custody/control location, Stripe support reference, accountable owner, and decision rationale. Property that remains blocked is included in applicable periodic reporting and retained with its audit trail for the legally required period. These controls govern the money only: they do not restore a suspended licence, delete self-hosted data, or permit a new transaction.

Our automated screening sources may differ by jurisdiction. Where a jurisdiction-specific source required by our control is not available through a reliable automated feed, registration and related Core distribution, trial, purchase, renewal, reactivation, or plan-change activity are held for documented operator review rather than approved from the global-list result alone. This hold currently applies when the registered company or checkout billing location is in Kazakhstan (KZ). Kazakhstan remains within our global B2B market; the hold is not a statement that the country or applicant is sanctioned. It ends only through the controlled manual-review process below after the available jurisdiction source and supporting identity information are recorded.

Controlled manual review and appeals. A company may be manually approved only on a documented verified-false-positive, jurisdiction-source-review, or applicable-authorization basis. The case must record a fresh active sanctions snapshot, the exact company-identity and match fingerprints, a detailed rationale, distinguishing facts, source/licence/counsel references, requester, reviewer, timestamps, and expiry. Where two or more authorized approvers are configured, the requester cannot approve their own case; a different authorized operator must approve it. While the Company has exactly one administrator, that sole operator may use a recorded solo-founder exception. Every manual approval expires no later than 30 days after approval. An identity change, a new or different match, expiry, or an independent export/enhanced-verification failure returns the company to review and may suspend affected distribution or Product/Component execution without deleting paid-source or self-hosted data.

An Account owner or authorized administrator may appeal a pending or blocked company decision through Account → Companies by providing a detailed statement and at least one supporting official/equivalent reference. An appeal opens a review case only: it does not automatically approve the company, restore Core or bundle distribution, collect a held payment, renew a subscription, or restore Product/Component execution. We may request more information, uphold the decision, or overturn it only through the controlled process and cannot override an applicable legal prohibition. We may limit the explanation where law restricts disclosure.

Company verification at transaction boundaries and during the relationship. The company (tenant) a licence is issued to is screened and registered before a trial or acquisition. We re-screen its persisted identity against the current sanctions snapshot before each Product purchase, automatic renewal, subscription reactivation, and Product Plan change, including a downgrade that changes the next renewal amount. These transactions fail closed when the snapshot is missing, inactive, or stale. A renewal or proration invoice that does not clear review is stopped before automatic collection where the payment flow permits and held in draft for review; no new paid-period licence is issued unless payment later completes lawfully. A purchase, trial, plan change, renewal, or reactivation may be refused or held while a company is unverified, under review, blocked, or cannot be screened against current data. That transaction refusal does not by itself revoke an entitlement already earned for the current paid period.

Optional enhanced KYB/KYC. The operator may enable a provider-managed business and representative verification control. It is off by default. While off, the sanctions, export, country, account, and company controls stated above remain fully applicable, but Railbase does not require the enhanced provider workflow. If enabled, the named company and the person acting for it must complete the hosted provider workflow configured for corporate-registry and company-document checks; ownership and management structure; directors, ultimate beneficial owners and representatives; identity-document and liveness checks where required; PEP, sanctions and adverse-media screening; and fuzzy, alias and transliteration matching. The provider may request company documents and personal identifiers such as name, date of birth, identity-document or passport data, address, role and ownership details. Those materials are collected in the provider's hosted workflow, not uploaded to the Customer's self-hosted Vault or ordinarily stored as document images by railbase.app.

When enhanced KYB/KYC is enabled, a provider approval for the current fingerprinted legal identity is an additional mandatory condition for Core distribution, Product trial or purchase, automatic renewal, reactivation, Product Plan changes, owned-Product installation, Component bundle grants, and Product/Component execution entitlement. A company-name, country, registration-number or tax-ID change requires a new provider approval. Missing credentials, provider outage, missing verification, pending/on-hold/resubmission status, or a non-approved decision fails closed. A manual sanctions decision in Cockpit cannot manufacture or override provider approval. A later provider hold or rejection may immediately suspend affected entitlements while preserving self-hosted Vault data. Disabling this optional control removes only the provider condition and reconstructs otherwise valid entitlements from preserved billing sources; it does not waive sanctions, export, payment, account or licence requirements.

Unavailable data is not a sanctions match. If the sanctions snapshot is missing, inactive, or stale, the monitor alerts and the periodic enforcement sweep waits for current data. That condition blocks the new transaction boundaries listed above, but does not on its own label a customer as sanctioned, cancel an existing subscription, or revoke the current paid-period entitlement. An already approved Account may continue an authenticated Core re-download/update, and a currently entitled Customer may request an existing Component bundle, during that dataset outage; account, payment, export-destination, optional enhanced-KYB/KYC, credential, node-binding, and current-entitlement gates still apply. A bundle grant issued before a later detection remains valid only for its existing 120-second lifetime.

We periodically re-screen active payers and licensed companies when a current snapshot is available, and also screen at transaction and existing-bundle-grant boundaries. A sanctions match suspends the affected server-side access in the same detecting request or sweep, including during a paid period; “immediate” does not mean at the instant an external authority publishes a change before Railbase has received and evaluated it. A match on the payer blocks Core downloads and updates and suspends all Product/Component entitlements on that billing Account; a match limited to one licensed company suspends only that company's entitlements while clean sibling companies continue. Connected instances normally receive the change on their next licence heartbeat. Node-bound Component tokens use a rolling validation lease of no more than 24 hours, capped by the paid term, so an instance that is completely disconnected may continue only until that lease expires; it receives no ordinary offline grace after lease expiry. Suspension preserves self-hosted Vault data but prevents licensed Component execution and new bundle grants. Future renewals may be scheduled to stop. Suspension is not an automatic refund, release, or transfer of funds; an already-paid current-period receipt enters the restricted-funds process above. Screening verdicts and manual-review rationale are ours to make and are disclosed only as law requires. A current controlled approval remains effective only for its recorded identity, exact match set and 30-day maximum term; it is not a permanent suppression list or silent automatic unblocking.

7. Refunds and chargebacks

Except where required by law, fees are non-refundable and there are no refunds or credits for partial periods, unused users or roles, trials, downgrades, unused company capacity, unused Product functionality, or Components included in a Product but not used by the Customer. Where a full refund, payment reversal, chargeback, or clawback occurs, the associated Product entitlement source may be revoked and affected Component execution may end. Your self-hosted data is not deleted by licence revocation, but continued use requires an active Product entitlement source.

8. Customer data and self-hosting

You retain rights to your own data processed by software you self-host. You are responsible for your deployment's data protection compliance, end-user notices, cookie notices, lawful basis, consent where required, security, backups, retention, deletion, access controls, export controls, and third-party integrations.

The railbase.app control plane necessarily holds account membership and scopes, registered-company details, billing/tax and invoice projections, subscription and product-component state, licence and deployment metadata, acceptance evidence, security/audit events, and KYC/sanctions records. It does not ordinarily receive the business records stored inside your self-hosted Vault. Revenue-based billing additionally receives the company-scoped aggregate described in Section 4 and the Privacy Policy. Accepted Cloud hosting and materials you deliberately submit for support are governed separately by the DPA. If you send us logs, database exports, documents, screenshots, support bundles, custom-development specifications, or other materials, you represent that you have the right to do so and that they contain no unnecessary sensitive, regulated, or third-party confidential data.

9. Translation module and machine translation

Where included in your expressly agreed Railbase scope, the Translate module provides machine translation for documents and inline text through a protected Component inside Railbase. It is not a separate customer-facing product. Machine translation can be wrong, incomplete, misleading, or unsuitable for a domain. Human review by a qualified person is required before legal, medical, financial, HR, compliance, official, customer-facing, or otherwise important use.

Depending on version and configuration, Translate may send document text or text segments to external translation engines such as Google Translate free endpoints, MyMemory, or Lingva instances. OCR may use local operating-system OCR capabilities or local tools such as Tesseract. You are responsible for determining whether those engines and tools are appropriate for the documents you process, including confidential, personal, regulated, export-controlled, or privileged materials.

We do not warrant translation accuracy, terminology correctness, formatting preservation, OCR accuracy, confidentiality of third-party translation engines, or fitness for regulated use. You are responsible for proofreading, legal review, and compliance of translated output.

10. Reviews, support, and submissions

If you submit a Product review, support request, development request, attachment, feedback, or other content, you grant us permission to use it to operate the Service, respond to you, moderate content, improve the Product, and, for approved public reviews, display the review with the author name and verified-owner status. You must not submit unlawful, infringing, confidential, personal, or sensitive data unless necessary and lawful.

11. Third-party services

The Service integrates or interoperates with third-party services, including payment processors, hosting providers, email providers, GitHub/release infrastructure, the enhanced KYB/KYC provider when that control is enabled, OAuth/SAML/LDAP identity providers configured by you, Stripe integrations configured in self-hosted deployments, and translation engines used by Products or Components. We are not responsible for third-party services, and your use of them is governed by their terms and privacy notices.

12. Intellectual property

The Service, including Railbase software, Products, Suites, Components, bundles, documentation, trademarks, artifacts, signatures, licence infrastructure, and related IP, is owned by the Company or its licensors and protected by law. These Terms grant you a licence, not a sale; all rights not expressly granted are reserved.

13. Acceptable use

You will not use the Service to violate law; infringe third-party rights; transmit malware; attack, scan, overload, or interfere with the Service or others' systems; bypass rate limits, license controls, signatures, or access controls; scrape non-public data; abuse support or review systems; or use the Service for high-risk activities where failure could lead to death, personal injury, or severe environmental or property damage.

14. Warranties and disclaimers

The Service is provided "AS IS" and "AS AVAILABLE", without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, title, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, secure, accurate, compliant with your local laws, or that defects will be corrected. For self-hosted deployments, you are solely responsible for deployment security, backups, operational reliability, and compliance. For expressly accepted managed hosting, operational responsibilities are allocated by the Cloud Service Schedule.

15. Limitation of liability

To the maximum extent permitted by law, the Company will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, goodwill, business interruption, inaccurate translations, tax consequences, or compliance failures. The Company's total aggregate liability arising out of or relating to the Service will not exceed the greater of (a) the amounts you paid to the Company in the 12 months before the event giving rise to the claim, or (b) USD 100. Some jurisdictions do not allow certain limitations, so some of the above may not apply to you.

16. Indemnification

You will indemnify and hold the Company harmless from claims, losses, liabilities, damages, penalties, and expenses, including reasonable legal fees, arising from your use of the Service, your self-hosted deployment, your data, your submissions, your tax or compliance obligations, your breach of these Terms, or your violation of law or third-party rights.

17. Term and termination

These Terms apply while you use the Service. An owner may export Account data or close the Account using the controls we provide. Account closure is immediate unless expressly stated otherwise: we attempt to cancel active subscriptions, block new commerce, revoke Product/Component execution and browser/machine credentials, and retain billing, tax, KYC, sanctions, security, and agreement evidence for applicable limitation and statutory periods. Closure is not an automatic refund. A cancellation that Stripe cannot confirm creates an action-required case while access remains revoked and commerce blocked; you should contact support if this occurs.

We may suspend or terminate your access, Account, downloads, subscriptions, or licences for breach, non-payment, suspected fraud, chargeback, sanctions/export risk, security risk, legal requirement, or discontinuation. On termination, affected Product entitlement sources end and Components stop executing when no other active source supplies them. Your self-hosted data is not deleted by us; you remain responsible for exporting or deleting it. Sections that by their nature should survive survive.

18. Governing law and disputes

These Terms are governed by the laws of the State of Wyoming, USA, without regard to conflict-of-laws rules. The exclusive venue for disputes is the state or federal courts located in Wyoming, and you consent to their jurisdiction. The U.N. Convention on Contracts for the International Sale of Goods does not apply.

19. Changes to the Service and Terms

We may modify the Service or these Terms. If we make material changes to the Terms, we will provide reasonable notice, for example by posting the updated Terms with a new effective date or by email. Application to an existing Customer remains subject to Section 21 and the applicable notice and acceptance process; publication or deployment alone does not amend an accepted Order.

20. General

These Terms are the entire agreement between you and the Company regarding the Service and supersede prior agreements. If any provision is unenforceable, the rest remains in effect. Our failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, financing, reorganization, or sale of assets. Notices to the Company should be sent to the address above or support@railbase.app.

21. Current platform offering and changed terms

The current company Products are Railbase Core, Accounting Suite and GRC Suite. Core is the execution foundation; both Suites run inside Core and require a valid Core entitlement for the same company. Each Suite is a separate Product subscription, not standalone software. Components and Connector have no separate customer price. Future industry solutions are not included or offered by this Agreement.

The current tariff and evidence rules are in Section 4. Future industry scope, infrastructure beyond the accepted Cloud allowance, external AI usage, implementation, integration, training and premium support require an explicit offer; they are not included by a diagram or documentation example.

The exact document version and hash are retained on explicit acceptance. This edition does not silently replace accepted Orders, prices or historical agreement evidence. Material changes use prospective notice and the applicable acceptance process. A software release, public page, licence heartbeat or billing metadata update is not acceptance of amended terms.

22. Contact

Silkway Tech LLC — 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA · support@railbase.app