Security · The isolation model

Your studio is yours alone.

One client, one studio, one set of keys. Here is the whole model, in plain terms.

Isolation · One studio per client

Every studio stands alone.

Each founder gets a whole studio of their own: its own server, its own database, its own keys. No shared platform sits underneath, and no path leads from one studio to another.

Three separate studios, drawn as three open rings that never touch. Three open rings stand apart with clear space between them. A small pulse of light travels the inside of the first ring, labelled Your studio, and never crosses into the others, labelled Another client. Your studio Another client Another client
The pulse stays inside your ring. It has no way to reach another studio, and another studio has no way to reach yours.
  • Its own environment. Each studio runs in its own isolated environment with its own credentials.
  • No shared memory. Studios share no database and no memory. There is no common store behind them.
  • No cross-reach. Your studio cannot see another client's work, and theirs cannot see yours.
The gate · A security boundary

Nothing leaves without your tap.

The approval gate is a security boundary, and it holds in code. Every post, every message, and every published page waits in your queue as a draft first.

A founder's morning queue: three pieces ready, each with its own Approve button.
The gate, holding three pieces of work.
  • No bulk approve. Each tap approves one piece. One tap can never release two acts.
  • No silent mode. No setting turns the gate off. It holds for every piece, every time.
  • Nothing outbound without a human tap. A draft you never approved never leaves your studio.
Your data · Plain files, no tracking

Your work stays yours.

Your work lives as plain files you can take with you. Your voice profile, your drafts, and your content are yours to download and keep.

  • Plain files. Your work is stored as plain files. There is no black box and no lock-in.
  • The product runs no analytics. The studio we build for you carries no tracking code and sends your activity to no one.
  • This page is honest about its own tag. This marketing site carries one Google Analytics tag. The studio you use carries none.
Access · You decide who is in

You control who reaches your studio.

You sign in with Google. A named allowlist controls who can reach your studio's chat, and you decide who is on it.

  • Google sign-in. Access uses Google OAuth. You grant it, and you can revoke it from your Google account at any time.
  • A named allowlist. Only the accounts you name can reach your studio's chat. Everyone else is refused.
  • Calendar access is optional and read-only. If you connect a calendar, the studio only reads your events. You can disconnect it and the studio keeps working.
Plainly · What we do not claim

What we will not pretend.

  • No compliance certifications yet. We hold no formal security certification today, and we will not pretend otherwise. When we earn one, we will name it here.
  • No client names and no case studies. Our clients did not sign up to be marketing. The work on our examples page carries stand-in brand names for that reason.
  • A full record when something breaks. Every act leaves a receipt. When something goes wrong, the record shows exactly what happened.
Next step

Questions about any of this belong on the call.

Book a call and ask anything about the model. You can also read the Privacy Policy and the Terms of Service, or write to nassim@dentesleo.com.