PairRail
Product Score Onboard Protocols Verify Pricing About
Log in
Terms Privacy Security DPA Subprocessors FAQ Support

Trust

Security & Responsible Disclosure

Last updated: September 25, 2026 · Operators of pairrail.com (“PairRail”)

PairRail Atlas handles seller commercial data and authentication for a multi-protocol agent-readiness control plane. We take security seriously and welcome good-faith research that helps keep sellers and buyers safe.

Security posture (high level)

  • Platform — Atlas runs on Google Cloud: Firebase (Authentication and Hosting), Cloud Run for the API and protocol gateway, and Gemini / Vertex AI for commercial-truth extraction. Cloudflare provides DNS, CDN, and optional edge telemetry where configured.
  • Authentication — Seller console sign-in via Firebase Authentication (Google / GitHub). Operator access is restricted to designated PairRail accounts.
  • Transport — HTTPS for pairrail.com; CDN and edge protections via Cloudflare where configured.
  • Separation of concerns — Public protocol endpoints serve published commercial projections; console and admin APIs require authentication and role checks.
  • Operational telemetry — Seller auth/action and protocol usage events may be stored at the edge (Cloudflare D1/R2) for reliability and abuse detection; operator product actions are not forwarded into that seller telemetry path.
  • Enterprise controls — Stronger isolation, signing, and key-management options (for example Cloud SQL with row-level security and Cloud KMS) are available for contracted Enterprise deployments; they are not implied for every Sandbox or Pro tenant.
  • Billing — Card data is handled by the payment provider; PairRail receives entitlement and subscription metadata.

This page is not a warranty or audit certification. We do not currently publish a SOC 2 report or a pentest letter. Controls evolve as the product matures.

Where Customer Content lives

  • Catalog and workspace state — durable state in Google Cloud Storage, served by Cloud Run in us-central1.
  • Sign-in — Firebase Authentication.
  • Extraction — Vertex AI / Gemini when you run a model extract, in Google Cloud.
  • Edge telemetry and feedback — Cloudflare D1 and R2, for seller users, not operator product actions.
  • Atlas subscription billing — Dodo Payments. We store entitlement metadata, not card numbers.
  • Mail — Resend for transactional messages.
  • Connectors you enable — Stripe, Chargebee, HubSpot, or your webhook, using tokens you save. See Subprocessors.

Access control

  • Seller console requires a signed-in Firebase user (Google, GitHub, or email code).
  • Workspace roles (Owner, Publisher, Editor, Viewer) gate publish, pause, machine keys, invites, and billing. Operator access is allowlisted, not open to every PairRail login.
  • Published protocol surfaces serve only what you published. Acting on a catalog requires a seller-approved machine credential.
  • Agent secrets (pat_…) are shown once at issue, approve, or rotate. We do not re-display plaintext secrets later.
  • Integration tokens are stored for the workspace that saved them and used only to call that connector.

Backup and offboard

Durable catalog state is kept in Google Cloud Storage. Edge telemetry is operational, not the system of record for prices. To delete a workspace, the owner emails support@pairrail.com. We take down that seller’s published rails, remove or anonymize Customer Content we no longer need, and confirm. Backups and security logs may remain for a limited period. Details sit in the Data Processing Terms.

Retention

Sandbox keeps about 14 days of activity. Pro retains audit trail and catalog versions for 90 days. Enterprise can extend retention under contract.

Incident response

Report suspected incidents and vulnerabilities to security@pairrail.com. We acknowledge when practicable, prioritize by severity, and notify affected customers when a fix is deployed if you gave us a valid contact. We do not run a 24/7 SOC. Production-blocking issues should also go to support@pairrail.com with subject P1.

Responsible disclosure

If you believe you have found a vulnerability in PairRail Atlas or pairrail.com, please email security@pairrail.com with the subject line Security disclosure. support@pairrail.com still reaches us if the security mailbox is unavailable.

Include:

  • A clear description of the issue and potential impact.
  • Steps to reproduce (proof-of-concept limited to what is necessary).
  • Affected URLs, endpoints, or console flows.
  • Your contact information and preferred credit name (optional).

Please do

  • Give us a reasonable time to investigate and remediate before public disclosure.
  • Limit testing to accounts and data you own or are authorized to use.
  • Avoid privacy violations, data exfiltration beyond proof, and service disruption.

Please do not

  • Access, modify, or delete other customers’ catalogs, pricing, or evidence.
  • Execute denial-of-service, social engineering of PairRail staff or customers, or physical attacks.
  • Introduce malware or ransomware.
  • Publicly disclose exploit details before we confirm a fix or mutually agree on timing.

Scope notes

In scope: pairrail.com application surfaces you reasonably believe we operate (console, APIs, protocol endpoints, edge telemetry/feedback paths). Out of scope unless we say otherwise: third-party services (Firebase, Google, GitHub, Cloudflare, payment providers) — report those to the respective vendor; misconfigured personal forks; and issues requiring unlikely user interaction with no security impact.

Our commitment

We will acknowledge receipt when practicable, prioritize based on severity, and notify you when a fix is deployed when you provide a valid contact. We will not pursue legal action against researchers who comply with this policy in good faith.

We do not currently operate a paid bug bounty. Recognition may be offered at our discretion.

Contact

security@pairrail.com · Subject: Security disclosure

Related: Subprocessors · Data Processing Terms · Support hours

PairRail

Governed pricing for the agents buying from you.

© 2026 PairRail. All commercial responses are indicative and governed by seller policy.
Legal Terms of Use Privacy Policy Code of Conduct Acceptable Use Security Subprocessors DPA Cookie Notice
Support Support FAQ About Home