Railway

United States · railway.app · 18 vendors

Railway is a cloud deployment platform that simplifies the process for developers to build, deploy, and manage applications and services. It provides an all-in-one intelligent cloud infrastructure, offering features like automatic scaling, monitoring, and database provisioning. The platform aims to reduce the complexity of traditional infrastructure management, allowing developers to focus on writing code.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-07-29 · revision 6

18 direct vendors, 214 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Railway exhibits high migration readiness due to its highly modern and flexible technical architecture. The core tech stack is cloud-native, containerized (Docker, OCI images), and microservices-friendly with features like automatic build detection (Railpack), horizontal/vertical autoscaling, and private networking. The use of modern technologies like Rust, GraphQL, PostgreSQL, Redis, MongoDB, and MySQL ensures compatibility and ease of integration with contemporary cloud environments. From a regulatory perspective, Railway's strong compliance posture (GDPR, HIPAA, SOC 2 Type II/3) and capabilities for global multi-region deployment and Data Processing Agreements indicate a robust understanding and implementation of complex compliance and data residency requirements, which are crucial for successful migrations. A significant advantage for migration readiness is the stated 'Total Vendors: 0' in the vendor relationships data. If this accurately reflects Railway's direct operational dependencies, it implies a complete absence of vendor lock-in for their core infrastructure, granting maximum flexibility and significantly simplifying any potential migration efforts. This contradicts other vendor data points provided, but if accurate for direct operational dependencies, it is a major strength. The main challenge in fully assessing migration readiness is the lack of financial stability data, which would typically inform the company's capacity to fund and execute large-scale migration projects.

Compliance

7 in-scope frameworks identified; showing 3.

HIPAA (source) — Partially Compliant

Railway is a general-purpose cloud infrastructure provider, not a healthcare company. However, as a cloud platform, Railway can and does host applications for healthcare customers who may process Protected Health Information (PHI). Railway explicitly lists HIPAA as a compliance framework on its Trust Center and has a published HIPAA Report (access-gated). As a cloud infrastructure provider acting as a Business Associate for healthcare customers, HIPAA compliance is relevant. Risk is Medium because: (1) Railway has proactively addressed HIPAA by publishing a HIPAA Report and listing it as a compliance item; (2) however, the HIPAA Report is access-gated and cannot be independently verified as a full BAA-backed attestation; (3) Railway's role as infrastructure provider means HIPAA obligations are primarily triggered by customer use cases, not Railway's own operations. Risk would be High if Railway hosts PHI without proper BAAs in place.

Evidence: https://trust.railway.com, https://trust.railway.com/?itemUid=aec41c33-0f3a-4030-ac59-49adfd4a975b&source=click, https://trust.railway.com/?itemUid=c41ff7d5-98e7-4d79-9594-fd8ef93a2838&source=click

ISO 27001 (source) — Assessment Required

No evidence of ISO 27001 certification was found in Railway's public documentation, Trust Center, or Privacy Policy. However, Railway has achieved SOC 2 Type 2, which covers substantially overlapping security control domains. The risk is Low because: (1) Railway's SOC 2 Type 2 provides equivalent or greater assurance for most enterprise customers; (2) Railway has a documented Information Security Program (referenced in DPA Exhibit C); (3) The absence of ISO 27001 is not unusual for US-based cloud startups/scale-ups that typically prioritize SOC 2 over ISO 27001 for their primary market. ISO 27001 would be more relevant if Railway significantly expands into EU/APAC enterprise markets where ISO 27001 is more commonly required.

Evidence: https://trust.railway.com, https://railway.com/legal/dpa

CPRA — Compliant

Railway is headquartered in San Francisco, California, making CCPA/CPRA directly applicable. Railway's Privacy Policy (effective April 20, 2026) contains a comprehensive 'U.S. State Privacy Rights' section explicitly addressing CCPA obligations. Railway has confirmed it does not 'sell' or 'share' personal data as defined under CCPA, and does not engage in cross-contextual behavioral advertising. Risk is Low because Railway has proactively and comprehensively addressed CCPA requirements in its Privacy Policy with specific California-resident rights, opt-out mechanisms, and contact procedures.

Evidence: https://railway.com/legal/privacy, https://railway.com/legal/dpa

Financials

Three-year financials

Financial Resilience Score: 7/10

Railway is a private, venture-backed US company with no publicly disclosed audited financials (no revenue, EBIT, or equity figures available). However, resilience is supported by a fresh $100M Series B raise in January 2026, bringing cumulative equity capital to approximately $125M. The company has strong blue-chip investor backing including Redpoint Ventures, Unusual Ventures, TQ Ventures/FPV, Lachy Groom, and prominent angels from GitHub, Vercel, Datadog, Segment, and Cockroach Labs. Product-led growth is evident with users scaling from ~250k in mid-2024 to over 2 million by January 2026 (roughly 8x in 18 months), and notable enterprise customers including TripAdvisor, Automattic, Mercado Libre, Cognizant, and Bilt provide reference-quality revenue signal. The usage-based pricing model aligns incentives and generates recurring metered revenue with typically strong net revenue retention characteristic of PaaS infrastructure businesses. Key risks include high opacity (no verification of profitability, burn, or runway), intense competition from Vercel, Render, Fly.io, Heroku, Netlify, and hyperscalers, and rising capital intensity from building own bare-metal datacenters (Railway Metal Gen 2), which shifts the business from capital-light software toward hardware-adjacent economics. Residual GCP dependency (highlighted by a May 2026 account suspension incident) and potential customer concentration also represent operational risks. On balance, the strong recent capitalization, elite investor syndicate, and hyper-growth user metrics support a moderately high resilience score despite the absence of financial disclosure.

Key strengths: Fresh $100M Series B raised January 2026, ~$125M cumulative equity capital, Blue-chip investors: Redpoint, Unusual, TQ Ventures/FPV, Lachy Groom, Elite angel roster: GitHub, Vercel, Datadog, Segment, Cockroach Labs founders, Hyper-growth: 250k → 2M+ developers in ~18 months, Usage-based pricing with recurring metered revenue, Enterprise customer traction: TripAdvisor, Automattic, Mercado Libre, Cognizant, Bilt, Vertical integration via own bare-metal datacenters (Railway Metal)

Risk factors: No public disclosure of revenue, EBIT, equity, burn, or runway, Intense competition from Vercel, Render, Fly.io, Heroku, Netlify, and hyperscalers (AWS, GCP, Azure), Rising capex intensity from building own datacenters, Residual GCP dependency (May 2026 account suspension incident), Undisclosed customer concentration risk, Macro/interest-rate sensitivity for future fundraising or exit, Valuation undisclosed; multiple compression risk in late-stage cloud/PaaS peers

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report