Security and reporting
What RailFi checks, how to spot a fake RailFi email, and how to report a problem.
On this page
Before anyone sends, RailFi checks the address, the network, the OFAC list and the link. No system removes all risk; the test send is your safety net.
In beta
Login links, anti-phishing codes, the audit history and the checks below are in beta with RailFi payment links, for invited contractors. Every form on the site is rate-limited.
What RailFi checks
- Address format and checksum, and that the address matches the network: Networks and wallet addresses
- The U.S. Treasury OFAC SDN list: Sanctions screening
- That the payment link hasn't been changed, and that the payer confirms twice: Invoices and payer instructions
- Repeated requests from one connection are limited
RailFi does not check the name on your provider account; your provider does. Identity and anti-money-laundering checks are your provider's job.
Login
- No passwords. You log in with a link sent to your email.
- Each link works once and expires after 15 minutes.
- A login lasts up to 12 hours. Changing your payout address needs a fresh link.
- Your account page lists active sessions, with a "Log out everywhere" button.
Spotting a fake RailFi email
Your account page shows a 3-word anti-phishing code that belongs to you. Every RailFi email to you starts with that code. If it's missing or different, the email isn't from RailFi: don't click, don't pay.
Audit history
Every step on an invoice (created, screened, link opened, payer confirmed, test sent, receipt confirmed) is recorded with its time in IST. RailFi's code only adds events; it never edits or deletes them. Each event includes a hash of the one before, so a changed record shows up as a broken chain. You and your payer can see the timeline.
What RailFi never asks for
We never ask for wallet keys, seed phrases, or bank passwords. RailFi never changes payment details by email.
Reporting a problem
Email forge7408@agentmail.to with "Security" in the subject. Include what you found, how to reproduce it, and the page or invoice ID involved. Please don't access other people's data or send real money while testing.
RailFi doesn't run a paid bug bounty. The same contact is published in /.well-known/security.txt (RFC 9116), and the Security page has more detail.
Last updated 30 September 2026. Something unclear or wrong? Tell us.