Skip to content
Foxx Cyberfoxxcyber/docs

Railway-Hosted Products

The security model for our commercial SaaS — Praevio, RailCompliant, and other apps that run on Railway. Different from the Bedrock platform, and honest about it.

Several Foxx Cyber products run as containers on Railway (or, for the GRC tools, self-hosted) — not on the dedicated AWS infrastructure the Bedrock platform uses. The Bedrock System Security Plan does not describe them.

These fall into two groups with different data sensitivity:

  • Commercial SaaS — Praevio and RailCompliant. No Controlled Unclassified Information (CUI). Payments via Stripe.
  • Compliance / GRC tools — Bedrock RMF and Bedrock AFT. These manage the customer's own compliance data. Bedrock RMF in particular handles RMF authorization artifacts and uploaded evidence that may contain CUI, depending on the deployment.

This section is their security story, told separately and honestly.

Do not read "runs on Railway" as "handles no CUI." That is true for Praevio and RailCompliant; it is not true for Bedrock RMF, which manages SSPs, POA&Ms, and uploaded evidence. See the Product Security Matrix.

Draft — every claim on these pages must be verified by the product owner before publishing. Hosting details, data-residency, encryption specifics, backup cadence, and payment handling are written here from engineering knowledge and are not yet confirmed for customer-facing publication. Security claims have to be exactly right; verify each one against the actual deployment, and soften or remove anything uncertain rather than rounding up.

Which products this covers

ProductWhat it isCUI?
PraevioAthlete-development / coaching SaaS (health & fitness data, including minors')No
RailCompliantFRA locomotive maintenance & compliance SaaSNo
Bedrock AFTAssured-file-transfer approval workflow (stores request records + classification labels, not file contents)Metadata/labels only
Bedrock RMFNIST RMF / ATO authorization tool (SSP, POA&M, evidence)May contain CUI

See the Product Security Matrix for the full mapping, including which Bedrock-branded products are not on the CUI platform.

What the model is — and isn't

It is a modern commercial-SaaS security posture: encrypted transport, managed and access-controlled infrastructure, least-privilege application authentication, tenant isolation enforced in the application, and payments handled by a PCI-compliant processor so card data never touches our systems.

It is not the Bedrock AWS platform. There is no AWS GovCloud boundary and no air-gapped assessor application, and no NIST SP 800-171 System Security Plan governs these apps as running systems. For the commercial SaaS products (Praevio, RailCompliant) that also means no CUI at all — a lighter model is the correct model for a product that never handles it.

The GRC tools (Bedrock RMF, Bedrock AFT) are different: they exist to manage a customer's own compliance data, which for Bedrock RMF can include CUI. There the relevant controls are the ones around the specific deployment, not a blanket "no sensitive data" claim.

The goal of this Trust Center is to be precise about which model protects your data — not to imply every product carries the heaviest one, and not to imply the lighter-hosted products are all free of sensitive data.

What these products share with everything else

  • Built with VibeSecOps. Same rulebook, same machine-enforced CI gates, same human verification as the Bedrock platform. The hosting differs; the engineering discipline does not.
  • One vulnerability disclosure process.
  • Least-privilege access and encrypted transport as baseline expectations, not optional extras.

Last updated August 19, 2026