Poliogo

Connect Railway

Connect Railway to confirm which service your policies cover and detect tools from variable names.

How it connects
Read-only OAuth
Setup time
Under 60 seconds
Access
Read-only

How the connection works

  1. Connect accountApprove the integration on the provider's own screen.
  2. Select projectYour projects and their production URLs are listed for you.
  3. Detection stays onVariable names are re-read on each scan, so a new service is noticed.

What it looks like once connected

An illustration of this connection inside your Poliogo dashboard — not live data.

Live sync activeExample
acme-api · web

Detected in this project

  • STRIPE_SECRET_KEYname only — value never read
  • POSTHOG_API_KEYname only — value never read
  • SUPABASE_URLname only — value never read
  • OPENAI_API_KEYname only — value never read
Last scan: 6 minutes ago3 documents up to date
Variable names only. Poliogo never requests a value, and no table in the database has a column to keep one in.

Exact permissions requested

Every permission this connection asks for, named as Railway names it on its own consent screen — so you can compare this table to what you are shown.

PermissionGrantWhat it is used for
Projects: ReadReadList your projects, services and their domains.
Variables: Read (names)ReadRead variable names to detect services. Values are never requested.
DeploymentsNot requestedNot requested. Nothing is deployed or changed.

Setting it up

What you do, and what you will be looking at while you do it.

  1. Connect your Railway account

    Press Connect Railway below and approve read access. Poliogo only ever runs read queries against Railway's API.

  2. Pick a project and service

    Your projects, their services and the service domains are listed for you.

  3. Let it read the variable names

    Variable names are read to detect services; values are never requested. RAILWAY_* variables injected by the platform are ignored as platform noise rather than reported as vendors.

  4. Check what it found and generate

    Review the detected list, correct anything, and generate your documents.

  5. Want the deeper scan? Add the repo

    Connecting the repository Railway deploys from adds the full source sweep.

Poliogo · New projectExample

Choose how to scan your app

Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.

Hosting PlatformVercel, Netlify, Railway — connect your account. Cloudflare — paste a read-only token.Choose another way
VercelNetlifyRailwayCloudflare

Connect your Railway account and pick a service — nothing to type.

Connect your Railway account

Projects: ReadRead
Variables: Read (names)Read
DeploymentsNot requested

Granted on Railway's own screen — this panel can show it, never widen it.

Connect Railway

Pick a deployment

acme-apiacme-api.up.railway.app
acme-apiacme-api.up.railway.appacme-api-stagingacme-api-staging.up.railway.appacme-docsacme-docs.up.railway.app

Environment variables detected

STRIPE_SECRET_KEYStripe
POSTHOG_API_KEYPostHog
SUPABASE_URLSupabase

Names only. No value is requested, and no table in the database has a column to keep one in.

Project synced · 6 minutes agoRead my project
Tell us what you use instead
The Poliogo setup screen for Railway, drawn from the same catalogue the app reads. An illustration — not live data, and nothing here is clickable.

What Poliogo detects from Railway

The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.

What it reads

  • Your project or site list, so you can pick the right one instead of typing an address.
  • The production URL, which is what your policies name as the service they cover.
  • Environment variable names — enough to prove which services you use.

What it never reads

  • Environment variable values. They are never requested and never stored.
  • Your source code — a hosting connection does not grant repository access.
  • Anything writable. Nothing is deployed, changed or redeployed.

Ready to connect Railway?

The free plan covers one project with no credit card. You approve everything before a single document is written.

Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.