Skip to content
Launch Rail
Trust Center

Know what Launch Rail owns—and what stays yours.

This baseline documents current availability, the self-hosted data path, shared responsibilities, support boundaries, and the evidence that exists today. Planned controls are labeled as planned.

Security contact

security@launch-rail.com

Use this address for vulnerabilities, security-review requests, or data-flow questions.

Deployment models

Availability language is intentionally narrow so prospects can distinguish what they can use now from what is still being built.

Guided browser preview

Available

A deterministic, no-login product walkthrough. It uses preview data and does not issue live credentials.

Customer-owned AWS

Pilot

The supported design-partner path. Deployment runs from the customer environment with ambient AWS credentials.

Customer-owned GCP

Planned

Visible as the next deployment target. It is not represented as equal in readiness to AWS.

Launch Rail managed Cloud

Planned

No public trial or production availability is promised until the managed service passes its release gates.

Shared responsibility

Source ownership gives customers control. It also makes operational ownership explicit.

AreaLaunch RailCustomer
Application source and release artifactsProvide licensed source, version guidance, and eligible updates.Control repository access and approve adoption of each release.
Cloud account and credentialsGenerate and document infrastructure artifacts; never request stored cloud credentials.Own the account, IAM roles, approval boundaries, and credential rotation.
Runtime operationsProvide golden-path guidance and support within the purchased term.Operate availability, capacity, backups, observability, and incident response.
Data protectionDocument service data flows and supported security controls.Classify data, set retention, configure encryption, and meet regulatory obligations.
Application authorizationProvide policy primitives and integration examples.Define roles, policies, approval paths, and least-privilege access.
Upgrades and compatibilityPublish release metadata, compatibility guidance, and supported upgrade paths.Test in a non-production environment and schedule production rollout.

Self-hosted data flow

The production path is designed to run without handing Launch Rail standing access to the customer cloud.

  1. 1

    Release

    Eligible source and release metadata are delivered through the customer area.

  2. 2

    Plan

    The CLI resolves versions and previews infrastructure from the customer machine.

  3. 3

    Deploy

    Customer-approved tooling uses ambient AWS credentials locally. Credentials are not written to the manifest.

  4. 4

    Operate

    Application and customer data remain in customer-controlled runtime services. Support uses customer-approved diagnostics.

Vulnerability disclosure

Send reproducible details, affected versions, impact, and a safe proof of concept to the security contact. Do not access other tenants, degrade availability, or disclose a finding before coordinated remediation.

  • We confirm receipt and establish a private coordination channel.
  • We validate scope and severity before agreeing on remediation and disclosure timing.
  • We credit researchers only with their written consent.

Evidence availability

Shared-responsibility matrix
Published on this page
Deployment and data-flow summary
Published on this page
License and support summary
Published on this page
SBOM
Design-partner delivery target
Signed artifact metadata
Design-partner delivery target
Threat model and architecture diagrams
Pilot review package
Independent compliance certification
Not claimed

License and support lifecycle

Perpetual source license

The licensed source version remains usable under the final agreement after the update term ends.

12 months included

Updates and support are included for 12 months from the license effective date.

Optional renewal

Renewal extends update eligibility and support; it is not required to keep using the licensed version.

Customer-operated runtime

Cloud uptime, backups, capacity, and production response remain the customer's responsibility unless a separate service says otherwise.

This is a product summary, not the license agreement. Commercial rights, support scope, and remedies are governed by the signed agreement.

Roadmap and changelog

Roadmap labels communicate intent, not a contractual delivery date.

Now

Foundation packaging, client-side architecture builder, AWS design-partner path, and baseline Trust Center.

Next

Release-gated temporary sandbox tenants, Control Plane customer areas, and the scoped Agent Gateway pilot.

Later

GCP production path, managed Cloud evaluation, and demand-gated additional modules.

Trust Center baseline published

Initial deployment, responsibility, disclosure, license, support, evidence, and roadmap disclosures.

Read privacy terms

Review the architecture with us.

Design partners receive a scoped evidence review before the production deployment decision.

View the pilot