4 days ago
Hello,
I operate a small SaaS application hosted on Railway that stores personal
data of children and their parents (names, home addresses, parent contact
details, and allergy information). I am currently completing a privacy
compliance review with legal counsel under Israeli privacy law, and I need
written answers to three questions about how Railway handles this data.
-
Encryption at rest
Are Railway volumes encrypted at rest? If so, please confirm the
encryption standard used and whether this applies to the underlying
infrastructure automatically, or requires configuration on my side.
-
Log retention
How long does Railway retain application logs and deployment logs? Is
the retention period configurable, and can logs be deleted on request?
-
Data Processing Agreement
Please provide your standard Data Processing Agreement (DPA), along
with your current list of sub-processors and the regions in which
customer data is stored.
My project is hosted in the US West (California) region. A written reply I
can forward to legal counsel would be appreciated.
Thank you,
Avivit Viskin
1 Replies
4 days ago
All data at rest is encrypted using AES-256, including volumes and backups. This is automatic and requires no configuration on your side. The published control and supporting audit materials (SOC 2 Type II, SOC 3, encryption policy) are available at trust.railway.com for your counsel to retain directly.
Application and deployment logs are retained for 7 days on the Hobby plan (30 days on Pro, up to 90 on Enterprise). Retention is not individually configurable within a plan tier, and we do not offer on-request log deletion. For longer retention or custom handling, you can forward stdout to a third-party tool via a log forwarder.
Our Data Processing Addendum is published at railway.com/legal/dpa and is accepted as-is (it is not amended or supplemented for any customer). The current subprocessor list is at trust.railway.com/item/subprocessors. Deploy region selection controls where your workload and attached volumes run; your US West selection places them in California. Note that the DPA's Exhibit A describes no sensitive or special-category data processing. If any of your processing falls under HIPAA, a Business Associate Agreement is available on the Enterprise plan ($1,000/month minimum, 12-month commitment) and sits alongside the DPA rather than modifying it.
Status changed to Awaiting User Response Railway • 4 days ago