Skip to content

Trust & security

If you cannot prove it later, it did not happen.

PlaceRail is built so the record of a split survives a disagreement, a fall-off, and a lawyer reading it two years from now.

Tamper-evident event log

Every action is added to a running record, and each entry is locked to the one before it. If anyone tried to change history, it would show. We check automatically every hour and raise an alert if anything looks off.

Double-blind by construction

Masking is enforced at the data layer, not painted on the screen. Counterparty identity is only readable once a split agreement is fully executed, and reveal happens for both sides at once.

Row-level access control

Every table enforces row-level security. You can read your own records and the records of deals you are a party to — nothing else, including through the API.

Verifiable exports

Audit bundles ship as a signed PDF, an event-log CSV and a manifest of digests. The public verifier recomputes the chain and compares it to the seal without needing an account.

Neutral arbitration

Disputes escalate to an arbitrator role that is separate from both desks. Decisions are locked once issued, evidence access is recorded, and deadlines prevent an indefinite freeze.

Non-circumvention detection

When a revealed candidate shows up at a revealed client outside the recorded deal, PlaceRail flags it and notifies both affected recruiters rather than leaving it to be discovered.

Candidates first

The person being placed has rights on the rail too.

Representation is something a candidate grants, not something a recruiter claims.

  • Consent is scoped to a named client and role, never a blanket permission.
  • Every grant carries an expiry date and can be revoked at any time.
  • A reveal log shows the candidate exactly when their details were disclosed and to whom.
  • The candidate portal lists every active grant in one place.

Practices

How the platform is operated.

Authentication
Email and password with breached-password checking on sign-up.
Secrets
Webhook signing secrets are readable only by the server, never by the browser.
Signatures
Outbound webhooks are HMAC signed with a per-endpoint secret and rotation grace.
Monitoring
Hourly integrity sweeps plus an in-app compliance dashboard for exports and access changes.
Data location
US-only at launch. PlaceRail never takes custody of placement funds.
Evidence
Dispute files default to private; sharing is per-file, explicit and logged.
Honest limits: escrow and billing currently run in demonstration mode until a payment provider is connected, and email delivery of notifications and audit exports is inert until a sending domain is verified for this workspace. Everything else described on this page is live.

Put your next split somewhere it can be proven.

Create a free account and export the record of your first deal to see exactly what it contains.