StudioCheck ← Back to StudioCheck

Trust Center

Security

Last updated: July 24, 2026

Read-only by design

StudioCheck's connection to your booking software is architected to be read-only. Our infrastructure has no code path capable of writing to, modifying, or deleting records in your connected booking platform — it can only read the data required to generate your analytics.

Encryption

Data is encrypted in transit using TLS 1.2+ and at rest using industry-standard encryption (AES-256 or equivalent).

Read-only access

Booking-software integrations use scoped, read-only credentials. StudioCheck cannot write to, charge, or modify records in your source systems.

Access controls

Internal access to production data is limited on a least-privilege basis, logged, and reviewed periodically.

Monitoring

Infrastructure and application activity is monitored for anomalies, with alerting for suspicious access patterns.

1. Data Isolation

Each Customer's data is logically segregated within our infrastructure. Access controls are enforced at the application layer to ensure a Customer's account can only retrieve its own studio's data. We do not use one Customer's identifiable data to inform another Customer's analytics; any cross-account benchmarking (e.g., "top performer" comparisons) is derived exclusively from aggregated, de-identified figures that cannot be traced back to a specific studio.

2. Infrastructure & Hosting

The Service is hosted on infrastructure provided by reputable cloud providers ("Sub-processors") that maintain their own independent security certifications. A current list of infrastructure sub-processors is available on request. Production environments are separated from development and staging environments.

3. Organizational Security

  • Employee access to production systems requires multi-factor authentication.
  • Access is granted on a least-privilege, need-to-know basis and revoked promptly upon role change or departure.
  • Employees and contractors are bound by confidentiality obligations covering Customer Data and End Client Data.
  • Security-relevant changes to infrastructure are reviewed before deployment.

4. Compliance Roadmap

StudioCheck is an early-stage product built with security-first architecture from day one. We do not currently hold a SOC 2 or ISO 27001 certification. Formal third-party certification is on our roadmap as we scale; Customers with specific compliance or vendor-security-review requirements (including requests for a security questionnaire or DPA) should contact us directly at the address below — we're generally able to accommodate reasonable diligence requests even ahead of formal certification.

5. Incident Response

We maintain an internal incident response process to detect, contain, and remediate security incidents. In the event of a security incident affecting a Customer's data, we will notify the affected Customer without undue delay and, where required by applicable law, within the timeframe mandated by that law (e.g., 72 hours under GDPR for notification to supervisory authorities, and Customer notification promptly thereafter to support the Customer's own downstream obligations).

6. Responsible Disclosure

If you believe you have discovered a security vulnerability in the Service, please report it to hello@studiocheckapp.com before disclosing it publicly. Please include sufficient detail to reproduce the issue. We ask that you:

  • Give us a reasonable opportunity to investigate and remediate before any public disclosure;
  • Avoid accessing, modifying, or deleting data belonging to other Customers or End Clients;
  • Avoid actions that could degrade the Service for other users (e.g., denial-of-service testing).

We do not currently operate a paid bug bounty program, but we will acknowledge good-faith reports and credit researchers who responsibly disclose valid findings, at our discretion.

7. Your Responsibilities

Security is a shared responsibility. As a Customer, you are responsible for: safeguarding your account credentials; enabling any available account security features; promptly revoking StudioCheck's access to your booking software if you no longer wish to use the Service; and ensuring only authorized personnel at your studio have access to your StudioCheck account.

8. Contact

Security questions, vendor security reviews, or vulnerability reports: hello@studiocheckapp.com

General privacy inquiries: hello@studiocheckapp.com · See also our Privacy Policy.

Drafting note (remove before publishing): Every technical claim on this page (encryption standards, MFA enforcement, monitoring, incident-response SLAs) must be verified against what is actually implemented in production before publishing — this document should describe reality, not aspiration. Overstating security controls you don't actually have creates real legal exposure (FTC Act Section 5 "unfair or deceptive practices" in the US, and equivalent consumer-protection law elsewhere) if a breach later reveals the claims were inaccurate. Have your engineering lead sign off line-by-line, and revisit the Compliance Roadmap section once — and only once — a real audit is underway.