Security

Security at St8dio.

Protecting your business data is fundamental to how St8dio is built. Here's an honest overview of the security practices we follow.

Encryption

Data is encrypted in transit using TLS (Transport Layer Security) and at rest in the database. Passwords are never stored in plain text — they are hashed using industry-standard algorithms.

Access controls

Access to your data is restricted by role-based permissions. Users only see the modules and records they are authorised to access. Two-factor authentication (2FA) is available to add an extra layer of protection to your account.

Data isolation

Each business's data is logically separated using workspace-level isolation. Your records — contacts, invoices, employees, and more — are not shared with or visible to other St8dio customers.

Audit logging

Key actions within the platform are logged so that changes to permissions, data, and settings can be reviewed. This helps detect unauthorised activity and maintain accountability.

Regular updates

The platform is continuously maintained and updated to address known vulnerabilities and keep dependencies current. Security patches are applied as they become available.

Secure infrastructure

St8dio is hosted on reputable cloud infrastructure providers that maintain recognised security standards. Backups are taken regularly to support data recovery in case of incidents.

Your role in staying secure

Security is a shared responsibility. We recommend that you:

  • Use a strong, unique password for your St8dio account.
  • Enable two-factor authentication (2FA) when available.
  • Limit access to sensitive modules using role-based permissions.
  • Review your user list periodically and remove inactive accounts.
  • Contact us immediately if you suspect unauthorised access.

Found a security issue or have a question? Please reach out via our contact page. We take all reports seriously and will respond promptly.

This page describes our current security practices. It is not a certification or a guarantee, and we may update our practices as the platform evolves.