EVIDENCE YOU CAN REVIEW
A defined scope.
Recorded results.
Assess the controls and the evidence behind them before choosing an enterprise evaluation. Developer verification is one part of the release process.
Evaluation release candidate · 0.3.0-rc.16 · General availability not approved
It runs on an isolated computer with synthetic credentials, a verified local HTTPS certificate, durable SQLite writes and a simulated tool with a 5 ms delay. It is not a benchmark of the Railway service, a sustained load test, a customer result or a service-level commitment.
HTTPS workload and failure checks
Recorded developer run: 15 checks passed. 192 measured calls; zero external-provider or model calls.
| Measurement | Recorded result |
|---|---|
| Measured calls | 192 |
| Concurrent clients | 8 |
| p50 latency | 25.579 ms |
| p95 latency | 37.071 ms |
| p99 latency | 39.205 ms |
| Completed calls / second | 300.62 |
Latency includes the local HTTPS request, gateway checks, database work and simulated tool delay. Eight closed-loop clients wait for each response before their next request. Warmup calls are excluded. These conditions do not establish maximum capacity or performance with real tools.
What the exercise checks
- Unauthenticated, administrator, resource, origin and tool-access denials.
- Concurrent authorized writes and identical requests without duplicate tool execution.
- Approval before execution and rejection of repeat execution.
- Uncertain outcomes retained without automatic retry; a circuit stops repeated failures.
- Emergency pause, disabled LLM and workload-token revocation.
- Consistent database snapshot, audit checkpoint and completed-action persistence across restart.
Snapshot verification uses keys within the test environment. It does not prove independent recovery-key custody or recovery after loss of a hosting account. The exercise does not perform an identity-provider login or a detection-accuracy evaluation.
THE RELEASE PROCESS
Reproduce the result.
Inspect the limits.
The private release includes the source, test runner, report and source fingerprint. An authorized evaluator can run the same acceptance exercise. Packaging requires successful verification against the matching source.
Available development checks
Automated functional/security tests, a synthetic HTTP workflow, the HTTPS exercise, dependency audit, source scanning, container build/smoke, SBOM and configured HIGH/CRITICAL image scanning.
CodeQL remains skipped because of repository eligibility. These checks are not independent assurance or a certification, and cannot establish that vulnerabilities are absent.
BEFORE PRODUCTION
Open requirements
remain visible.
Independent security assessment; representative customer acceptance; independent recovery-key custody and disaster recovery; customer workload and failure testing; sustainable hosting and support; operator identity, product rights and commercial terms remain gates. Customer-specific integrations and optional payment activation need actual account validation.
The numerical classifier still has known detection gaps. The hosted paid LLM is disabled. The service is single-node, without high availability or native MCP transport. No acquisition interest, customer references, universal superiority or guaranteed protection is claimed.