Security and privacy

Trust principles, labeled by status

Only claim what is implemented or formally committed. Planned items stay labeled. ProofRail never holds merchant customer funds and never charges end buyers.

Current private-beta access is intended for sandbox, fictional, and non-sensitive test records. Real customer transaction evidence waits until remaining live-data readiness items (including the object-storage write path) are closed.

Private beta

What data the beta accepts

Private beta is for sandbox, fictional, and non-sensitive test records. We do not invite merchants to store real customer transaction evidence until the controls below are verified in the product.

Current private-beta access is intended for sandbox, fictional, and non-sensitive test records. Real customer transaction evidence waits until remaining live-data readiness items (including the object-storage write path) are closed.

  • Encryption at rest

    Implemented

    Sensitive buyer fields use application-layer encryption; the database and object store use platform encryption at rest. Private beta still limits merchants to sandbox and test data until remaining live-data readiness items close.

  • Tenant separation

    Implemented

    Merchant accounts are isolated with database row-level security and adversarial access tests. One tenant cannot read another tenant's evidence.

  • Clear source attribution

    Implemented

    Each evidence item carries its source class and trust level (T1–T6). Client/SDK events stay client-reported and are never shown as provider-verified.

  • Integrity checks

    Implemented

    Hash-chained ledger records, signed checkpoints, and offline bundle verification detect alteration. Tamper-evident — not a claim that records cannot be changed.

What this page does not publish

  • Cipher suites, key-management details, or infrastructure topology
  • Internal runbooks, repository paths, or threat-model worksheets
  • Implementation specifics that would help someone abuse a gap

Control labels above are high-level status only. Encryption at rest for real customer evidence is verified for public claims. Questions: sales@proofrail.site.

  • No custody of merchant funds

    Implemented

    Hard product rule. Not a payment processor or money transmitter.

  • No charging of buyers

    Implemented

    Merchants are billed. Buyers are not.

  • Encryption in transit

    Implemented

    Site and product endpoints are served over HTTPS.

  • Clear source attribution

    Implemented

    Each evidence item carries its source class and trust level (T1–T6). Client/SDK events stay client-reported and are never shown as provider-verified.

  • Integrity checks

    Implemented

    Hash-chained ledger records, signed checkpoints, and offline bundle verification detect alteration. Tamper-evident — not a claim that records cannot be changed.

  • Encryption at rest

    Implemented

    Sensitive buyer fields use application-layer encryption; the database and object store use platform encryption at rest. Private beta still limits merchants to sandbox and test data until remaining live-data readiness items close.

  • Tenant separation

    Implemented

    Merchant accounts are isolated with database row-level security and adversarial access tests. One tenant cannot read another tenant's evidence.

  • Least-data collection

    In development

    Marketing waitlist collects only submitted fields. Product follows least-data design.

  • Exportable merchant-controlled records

    Planned

    Exportable packages are a core product outcome; illustrations are fictional.

  • Configurable retention

    Planned

    Retention controls are planned, not generally available.

  • Role-based access

    Planned

    Role-based access is planned for the product.

  • Auditable account activity

    Planned

    Audit trails are planned; not claimed as live here.

Security questions

For security or privacy questions about the beta or the product, email sales@proofrail.site.

This page is a marketing overview, not a formal security whitepaper or audit report.