a day ago
Please direct this question to the Railway privacy/security team. For an app-review processor disclosure, we need the complete country list applicable to Railway-hosted application data, including support, engineering and administrative remote access, logs, backups, and relevant infrastructure subprocessors. The public DPA identifies primary processing in the United States, while the Trust Center lists some locations as Global, EEA/EU, or Selected Railway Region. Those labels do not identify every country. Is there a current public document with the complete applicable country list? If not, please confirm how to obtain a written country-only answer and identify a private contact route. We are not requesting confidential reports or sharing customer data, credentials, project identifiers or NDA material in this public thread. A related country-only question has already been submitted through the Trust Center; please advise the correct team and expected turnaround.
1 Replies
a day ago
We have a globally distributed team. When you explicitly ask for support, any access needed to investigate may come from wherever our team members work, and choosing a deploy region does not limit that access to the selected region. We will not be providing a list of countries that staff support access may come from, publicly or privately. That applies to app-review and vendor-questionnaire requests as well.
On storage: workloads and attached volumes run in the deploy region you select. Volume backups and PostgreSQL point-in-time recovery data stay in that same region. All logs (runtime, deploy, build and HTTP) are stored in US West, whatever the deploy region.
For infrastructure subprocessors and contractual terms, the published sources are the subprocessor list and the DPA. The DPA is the only data-processing agreement we offer, and we don't issue separate written country attestations.
Status changed to Awaiting User Response Railway • 1 day ago