Access isolation
Database row-level rules separate accounts and restrict private records to authorised roles.
Seguridad en Studio ATS
Studio trata datos comerciales, solicitudes de clientes y eventos de pago. Diseñamos los accesos y operaciones para que cada persona vea solo lo necesario y las acciones sensibles sean trazables.
Nuestro enfoque
No single control is presented as infallible. Isolation, server-side checks, restricted secrets, signed events and audit trails work together to reduce risk.
Database row-level rules separate accounts and restrict private records to authorised roles.
Short-lived, single-use login codes are stored as keyed hashes rather than usable codes.
Privileged credentials remain server-side and are used only by narrowly scoped services.
Sensitive financial and administrative changes create records that can be investigated.
Protección de datos
Commercial information is separated by account and purpose. Public forms do not turn private customer records into public data, and tracking identifiers are minimised or hashed where appropriate.
Production traffic uses encrypted HTTPS connections provided by the hosting platform.
Access policies are applied close to the data, in addition to checks in the application.
Administrative access is reserved for authorised operational needs.
You keep control of the business information and contacts entrusted to your Studio.
Pagos
Checkout and sensitive banking onboarding are hosted by Stripe. Studio receives signed events and the operational references needed to confirm a payment, refund or dispute; it does not store card or bank account details.
Responsabilidad compartida
We secure the platform and the services we operate. Customers and partners also protect their mailbox, devices and authorised access. The safest system is one whose responsibilities are understood.
Platform access, application updates, service configuration and investigation of reported incidents.
Accurate user access, protected email accounts and prompt reporting of suspicious activity.
Hosting, database and payment infrastructure within their respective security programmes.
Si algo parece incorrecto
Security reports are treated separately from ordinary commercial questions so that the team can qualify the issue and limit exposure quickly.
Send the affected page, time and observable behaviour without including passwords or card details.
We assess the scope and restrict the affected access or operation when necessary.
The cause is fixed, relevant evidence is preserved and affected parties are informed when required.
Describe the context and the Studio team will route it to the right person. Never send a password, login code or payment card number.