Payments
How our Railway-hosted products handle billing — card data never touches our systems.
Draft — verify before publishing. Confirm the payment-processor integration details for each product (and whether it runs in test or live mode) before this page is published.
Products that take payment — such as Praevio and RailCompliant — bill through Stripe, a PCI-DSS Level 1 certified payment processor. Card and bank details are entered directly into Stripe's hosted, tokenized flows and are never stored, logged, or processed by our applications.
What this means for your card data
- We don't see your full card number. Payment details go to Stripe, not to our servers. Our application receives a token and a status, not the card itself.
- We don't store payment credentials. There is no card data at rest in our databases to breach.
- PCI scope stays with the processor. Because card data never enters our systems, the heavy PCI-DSS obligations sit with Stripe, where they belong.
What our application does store
Our systems keep the non-sensitive billing metadata needed to run the service — for example, a Stripe customer or subscription identifier, plan/tier, and billing status. These identifiers let us reflect your subscription state without ever holding your card.
If a product is currently operating in Stripe test mode (some are, during beta), no real charges are made. The product's own pages and your agreement are the source of truth for billing status — confirm the current mode per product before relying on this page publicly.
Reporting a billing security concern
Suspected billing or payment security issues go through the same vulnerability disclosure process as everything else. For account or billing support (not a security issue), see Getting Support.