Security at RailFi
Before anyone sends, RailFi checks the address, the network, the OFAC list and the link. No system removes all risk; the test send is your safety net.
What RailFi checks
- Address format and EIP-55 checksum (Ethereum, Polygon PoS, Base, Arbitrum) or 32-byte base58 (Solana). Token contract and zero addresses are refused.
- Network: you pick it explicitly; Solana vs EVM mismatches, Tron and Bitcoin addresses are blocked. The payer re-selects the network before seeing how to send.
- Sanctions: every address is checked against the U.S. Treasury OFAC SDN list (digital currency addresses), refreshed daily, when an invoice is created and every time the payment page opens. If the list copy is more than 72 hours old, or the check fails, RailFi pauses and shows no instructions. OFAC says its address list is not likely to be exhaustive; this is a list check, not an AML risk score.
- Signed payment links: any change to the ID, amount, address or network shows a warning instead of the address. Anyone can check an ID and address at /verify.
- Double entry: the payer re-selects the network and types the last 6 characters from their own wallet's confirm screen.
- Test send first: the full amount is only shown after the payee confirms the test arrived (or the payer accepts the risk of skipping it, which is logged).
- Magic-link login (single use, 15 minutes), sessions of 12 hours, and "Log out everywhere".
- An append-only audit trail per invoice, with each event hash-chained to the one before, shown in IST.
- Rate limits on every form and action.
What your provider does (not RailFi)
- RailFi isn't a bank or money transmitter. Your payout provider is the regulated party. Check their licence page.
- Identity checks (KYC), full AML screening and transaction monitoring.
- Account name checks. RailFi verifies your email; it does not verify the bank or provider account holder's name.
- RailFi never holds your money, so there's nothing of yours at RailFi to lose.
Spotting fake RailFi emails
When you log in, your account page shows a 3-word code, like amber-otter-lantern. Every real RailFi email to you starts with "Your RailFi code:" and that code. No code, or a different one, means it isn't from RailFi. RailFi never asks for keys, seed phrases or passwords, and never changes payment details by email.
Report a security issue
Email forge7408@agentmail.to with the steps to reproduce. We aim to reply within 3 business days. There is no bug bounty.
Good-faith research is welcome: if you avoid privacy violations, data destruction and service disruption, only test against your own accounts, and give us reasonable time to fix before disclosure, we won't pursue legal action over your research.
Machine-readable contact: /.well-known/security.txt
Machine-readable contact: /.well-known/security.txt (RFC 9116). More detail in the security docs.