Trust

Security

What is encrypted, what is logged, what is never stored, and who else sees the data. Written down in enough detail to judge for yourself, because no certificate stands in for it here.

Claims as at 26 August 2026. Words cut 2 September 2026. Nothing changed but the length. Written by Jimi Barkway.

In plain English

The biggest thing on this page: your affiliates' money never passes through us, so there is no pot of other people's money here to lose. We are not SOC2 certified and we do not pretend to be. What we do instead is below, in enough detail to judge for yourself.

01 The money

Nobody's money passes through us

Payouts are non-custodial by design. You connect your own PayPal Business, Wise Business or Payoneer credentials. We tell your PayPal or Wise account to pay, with your token to send your money to your affiliates. We never hold, receive, route or control any of it. We take 0% of it. And there is no platform-level payout credential anywhere in the system for anyone to steal.

How a payout moves on AffiliateRailMoney goes from your PayPal or Wise account straight to your affiliate, the same width at both ends. AffiliateRail works out the amounts and tells your account to pay; it never receives the money.$2,500you sendthey getAAffiliateRailworks out who is owed whatThe money never enters AffiliateRail.It goes from your own account to theirs, at thewidth it left.

02 No custody

Why there is no pot of money here to lose

Most of the harm an affiliate platform can do is to money in its custody. There is none here. It is also why your affiliates never do an identity check with us: you pay them, not us. Who holds the money sets the same question out across the category, with sources and dates.

What follows

  • Nothing in custody

    Nothing to freeze, lose or mismanage.

  • No identity check with us

    Your affiliates are paid by you, not by us.

  • Sources and dates

    Who holds the money, across the category, on /custody.

03 No certificate

We are not SOC2 certified

No SOC2, no ISO 27001, no audit under way. At our size the certificate would cost more than the engineering it certifies. Buying one this year would mean building less of the thing that protects your data.

If your procurement process needs SOC2 before you can sign, we are not the right supplier yet. We would rather say so now than six weeks into a questionnaire.

What we do not have

  • No SOC2

    And no ISO 27001.

  • No audit under way

    The certificate would cost more than the engineering it certifies.

  • A straight answer

    If procurement needs SOC2 first, we are not your supplier yet.

04 Encryption

Encryption

In transit: TLS everywhere, including the tracking script and the short-link redirector. At rest: the whole database, at the provider.

Twice over, for the two things that matter most. Payout credentials and tax form contents are encrypted again inside the application, under a per-deployment key. One envelope format carries a key id, so a key can be rotated without re-encrypting every row on the same day. The key is not in the database. Someone holding a copy of the database holds neither.

Encrypted twice overThe database is one sealed envelope. Inside it, payout details and tax forms sit in a second envelope, sealed with a key that is not stored in the database, so a copy of the database holds neither.payout details and tax formsthe database, encrypted at restThe keykept outside the databaseA copy of the database holds neither.

05 Access

Access

  • Two-factor authentication on accounts.
  • API keys are stored as a SHA-256 hash and shown once. Scopes are checked on the server, never in the page.
  • Plan limits are server-side. A feature you are not on is refused by the server, not hidden by the interface.
  • One tenancy check on every query. The isolation is tested with two customers seeded side by side, not asserted in a document.
  • Signed webhooks. A webhook is AffiliateRail calling your server the moment something happens, and every one of ours is signed so you can prove it came from us. The secret rotates and the old one keeps working for 24 hours, so rotating is not an outage.
A signed webhookEvery webhook carries a timestamped signature in the Rail-Signature header, so the receiver can check it came from AffiliateRail and was not replayed.Rail-Signaturea timestamp inside thesignatureverified on arrivalA stale delivery fails the check, and a rotatedsecret keeps a grace window.

06 The record

The audit log

Every consequential action is recorded: who did it, what changed and when. The deletion record includes the deletion itself. That is the one entry an erasure must never be able to remove.

What is recorded

  • Approvals

    Partner approvals and commission decisions.

  • Money

    Payout batches.

  • Keys and data

    Key creation, data exports and deletions, including the deletion itself.

07 Idempotent

Money that cannot be paid twice

Every write that moves money carries a deterministic idempotency key on a unique database index. A retry, a double click or a replayed webhook produces the same single result.

Payout methods can fail after they have accepted a request. So a payout is never marked paid because PayPal or Wise said 200. It is marked paid when the money moved.

Money that cannot be paid twiceA retry, a double click and a replayed webhook all arrive at one idempotency key, and one key produces one payout.A retryA double clickA replayed webhookOne keypayout:prt_8a…:2026-09AOne key, one payout, once.Marked paid when the money moved, not whenPayPal or Wise said 200.

08 Backups

Backups and restore

The database runs on managed Postgres with a point-in-time history window of 7 days in production. Restoring means branching the database as it was at an instant. The live copy is untouched while we look at the old one.

We run a restore drill and log the result with the numbers: tables, rows, and how long end to end took. The log is short and the numbers in it are real. Calling it anything grander would be dressing it up.

The restore drill

  • 7 days

    Point-in-time history in production.

  • A branch, not a rollback

    The live copy is untouched while we look at the old one.

  • Logged with numbers

    Tables, rows, and how long end to end took.

09 Your browser

What is in your browser

The dashboard keeps your session, which program you are looking at, and your security settings. Analytics does what you told the banner. Accept and it keeps a cookie. Refuse and it counts the visit with nothing stored in your browser at all.

Change your answer any time from Cookie choices in the footer. The privacy policy names what is stored either way.

Kept in your browser

  • Your session

    And which program you are looking at.

  • Your security settings

    Including two-factor authentication.

  • An analytics cookie, only if you accept

    Refuse, and the visit is counted with nothing stored at all.

10 The recording

What a session recording holds

The part that matters on screens full of your affiliates' details does not depend on that answer. The text you click is never captured, and the session recording is fully masked: pointer, clicks and scrolling, with every text node and every input blanked before anything leaves your browser. An email address cannot be read off a recording that never held one.

The Partners screen as a session recording holds it: every text node and every input replaced by asterisks before the frame leaves the browser, with only the layout, the buttons and the status chips still readable
What a recording holds: the Partners screen, masked by the same rule the replay uses

11 Sub-processors

Who else sees the data

Every company that processes data on our behalf is listed at affiliaterail.com/subprocessors: what it does, where it processes, and the transfer mechanism. We give 30 days' notice before adding one. Two of them have no confirmed transfer terms yet. The page says which two, and why that does not put your data at risk.

On the list

  • What each one does

    And where it processes.

  • The transfer mechanism

    Named for each.

  • 30 days' notice

    Before any new one is added.

12 Found something?

Reporting a vulnerability

Email security@affiliaterail.com. Tell us what you found, how to reproduce it, and what you think it lets someone do. You get a human reply within two working days and a fix timeline within five.

Please do not open a public issue, and please do not test against data that is not yours. A test account on a trial with its own affiliates is fine. Someone else's program is not.

What you get back

  • Two working days

    A human reply.

  • Five

    A fix timeline.

  • Thanks in public

    With credit if you want it. No paid bounty.

13 Procurement

Answering a questionnaire

Most of what a procurement questionnaire asks is on this page, the sub-processor list and the data processing agreement, which is already in force and prints. For anything else, email support@affiliaterail.com. A person answers, usually the one who wrote the code.

The three documents

  • This page

    What is encrypted, what is logged, what is not stored.

  • The sub-processor list

    Every company that touches the data.

  • The data processing agreement

    In force, and it prints.

Gathered from above

What is not stored here

Every line below is a claim made on this page, collected in one place.

Not stored, not held, not captured

  • Your affiliates' money

    Never held, received, routed or controlled. 0% of it is taken.

  • A platform-level payout credential

    There is none anywhere in the system for anyone to steal.

  • The encryption key for payout credentials and tax forms

    Not in the database. A copy of the database holds neither.

  • Your API keys

    Stored as a SHA-256 hash and shown once.

  • The text you click

    Never captured by analytics.

  • Text or inputs in a session recording

    Every text node and every input is blanked before anything leaves your browser.

  • An analytics cookie, if you refuse

    The visit is counted with nothing stored in your browser at all.

Questions

Common questions

Is AffiliateRail SOC2 certified?

No. No SOC2, no ISO 27001, no audit under way. At our size the certificate would cost more than the engineering it certifies. If your procurement process needs SOC2 before you can sign, we are not the right supplier yet.

Does any money pass through AffiliateRail?

No. Your affiliates' money is never held, received, routed or controlled by us, and 0% of it is taken. Payouts run through your own PayPal or Wise account with your own credentials.

How are payout credentials and tax forms protected?

The database is encrypted at rest. Inside it, payout credentials and tax forms are encrypted again under a key that is not stored in the database. A copy of the database holds neither.

What does a session recording contain?

Every text node and every input is blanked before anything leaves your browser. Analytics never capture the text you click. If you refuse the analytics cookie, the visit is counted with nothing stored in your browser at all.

Fourteen days

Nothing of yours to lose here, and fourteen days to check

No card, and 30 days to ask for your first payment back. The sub-processor list is at affiliaterail.com/subprocessors. Questions to support@affiliaterail.com, and a person answers.