Security direction

Security claims should follow evidence.

Railixa is not presented here as certified, production-hosted, or approved for safety-critical use. The website identifies the security workstreams a real pilot would need to resolve.

Identity and access

A production design would define identity providers, strong authentication, role and line-level permissions, joiner-mover-leaver controls, privileged access, and auditable administrative actions. The current sign-in screen is visual only.

Data and infrastructure

Hosting region, encryption, key management, backup, recovery, retention, logging, subprocessors, and incident response would be selected and documented for the agreed pilot scope. No specific provider or region is claimed by this demo.

Rail and regulatory assessment

Railway safety applicability, NIS2 obligations, data protection roles, accessibility, supplier assurance, and relevant standards would require specialist assessment. Product copy must only reference alignment or certification after that evidence exists.