Authentication and tenancy
Authenticated product routes require a signed-in user and an active organization. Data access is scoped to that organization in server-side product flows.
Security & trust
This page describes current practices without claiming certifications or compliance conclusions that have not been independently approved.
Current practices
Authenticated product routes require a signed-in user and an active organization. Data access is scoped to that organization in server-side product flows.
Production traffic is served over HTTPS. Managed infrastructure providers supply encryption capabilities for data in transit and at rest; exact processor responsibilities are documented through provider terms.
Reach uses Stripe-hosted checkout and account-management flows. StudioAnchor does not use this public website to collect payment card details directly.
Reach maintains public discovery, authorization, token, and MCP endpoints. Access tokens are scoped and can be revoked; tool calls remain subject to workspace permissions and product controls.
Status
StudioAnchor does not currently claim SOC 2 certification, ISO certification, OpenAI endorsement, or a blanket legal conclusion that every use is GDPR- or CCPA-compliant. Those outcomes depend on documented controls, contracts, customer configuration, and—where appropriate—independent assessment.
We will update this page when a claim has an approval record and evidence that can be reviewed.
Your controls
Account administrators can manage workspace access and connected applications. Requests for data access, correction, export, or deletion can be sent to [email protected]. We verify authority before acting and may retain limited records when law, security, billing, or dispute obligations require it.
Send the affected URL, a concise description, and safe reproduction steps. Do not include unnecessary personal data or exploit customer information.
Email [email protected]