Skip to content

Security and reporting

What RailFi checks, how to spot a fake RailFi email, and how to report a problem.

On this page

Before anyone sends, RailFi checks the address, the network, the OFAC list and the link. No system removes all risk; the test send is your safety net.

In beta

Login links, anti-phishing codes, the audit history and the checks below are in beta with RailFi payment links, for invited contractors. Every form on the site is rate-limited.

What RailFi checks

RailFi does not check the name on your provider account; your provider does. Identity and anti-money-laundering checks are your provider's job.

Login

  • No passwords. You log in with a link sent to your email.
  • Each link works once and expires after 15 minutes.
  • A login lasts up to 12 hours. Changing your payout address needs a fresh link.
  • Your account page lists active sessions, with a "Log out everywhere" button.

Spotting a fake RailFi email

Your account page shows a 3-word anti-phishing code that belongs to you. Every RailFi email to you starts with that code. If it's missing or different, the email isn't from RailFi: don't click, don't pay.

Audit history

Every step on an invoice (created, screened, link opened, payer confirmed, test sent, receipt confirmed) is recorded with its time in IST. RailFi's code only adds events; it never edits or deletes them. Each event includes a hash of the one before, so a changed record shows up as a broken chain. You and your payer can see the timeline.

What RailFi never asks for

We never ask for wallet keys, seed phrases, or bank passwords. RailFi never changes payment details by email.

Reporting a problem

Email forge7408@agentmail.to with "Security" in the subject. Include what you found, how to reproduce it, and the page or invoice ID involved. Please don't access other people's data or send real money while testing.

RailFi doesn't run a paid bug bounty. The same contact is published in /.well-known/security.txt (RFC 9116), and the Security page has more detail.

Last updated 30 September 2026. Something unclear or wrong? Tell us.