14 days ago
Subject: Pre-sales technical & compliance questions — regulated fintech workload
Hello Railway team,
I'm evaluating Railway to host DheCash, a financial services platform (merchant payment gateway, mobile wallet, Visa card issuing, and an agent network) operating in Haiti. Because this is a regulated workload, I need documented answers to the questions below before committing. I've already requested access to the Trust Center documentation.
- PCI-DSS
- Is Railway listed as a PCI-DSS validated service provider (e.g. on the Visa Global Registry of Service Providers)?
- Can you provide an Attestation of Compliance (AOC) as a service provider?
- Do you have a PCI shared-responsibility matrix showing which requirements Railway covers and which remain mine?
- Data residency and subprocessors
- In which specific regions is my data stored and replicated?
- Can I contractually pin all workloads and databases to a single region?
- Which underlying cloud providers actually host the workloads in that region?
- Tenancy and isolation
- Is the Pro plan shared tenancy? What isolation controls are in place between tenants?
- From which plan can I get isolated or single-tenant compute, and at what cost?
- Can you provide documentation supporting a tenancy risk assessment for an auditor?
- Availability, backups and disaster recovery
- What is the contractual uptime SLA on Pro, and what remedies apply if it is missed?
- What is the backup frequency and retention for managed PostgreSQL?
- Is point-in-time recovery (PITR) available, and what are the documented RPO and RTO?
- Can I export backups to external storage that I control?
- Personnel access to production
- Can Railway engineers access my running containers and databases in production?
- Is there a mode that contractually or technically blocks that access outside of a HIPAA BAA?
- Are customer-facing audit logs available for any such access?
- Real cost estimate
Based on the following steady-state usage, what is my estimated monthly bill?
- always-on services / containers
- [Y] GB RAM and [Z] vCPU sustained
- managed PostgreSQL, approx. [N] GB storage
- approx. [T] GB monthly egress
Also: what is the egress rate per GB, and can I set a hard spend cap rather than a soft alert?
- Support and contracting
- What is the guaranteed response time on the Pro plan?
- Is there an escalation channel for production incidents?
- Is the Enterprise plan annual-commitment only, and what is the entry price point?
If some of these can only be answered under NDA, I'm happy to sign one. I'd also welcome a call once I have written answers to the PCI and data residency points, as those are decisive for us.
Best regards,
Christopher Jerome
Codeshell LLC
0 Replies
Status changed to Awaiting Railway Response Railway • 14 days ago