Also, with properly-configured ACLs, you should be fine using the JS SDK client-side with a Rails backend.