Security
How we run the platform, where data lives, and what we do not claim yet.
Last updated 29 August 2026
Security summary
AI Transform Studio is built for business teams who connect their own systems and model providers. This page describes how we handle security and data in plain language. It is not a certification claim.
Operator: AI Transform Studio Ltd (registered in England and Wales). Contact: support@aitransformstudio.com.
Architecture and regions
The product is a multi-tenant SaaS application. Customer data is separated logically by organization in the application layer. We do not claim dedicated databases or private networking for every customer.
Production application data and authentication run on Convex in the EU (eu-west-1, Ireland). The web app’s serverless functions run on Vercel in Dublin and Frankfurt (with a global edge CDN). Collaboration and visual rendering infrastructure run on Fly.io in Frankfurt (fra). Some subprocessors (for example email) may process data outside the UK/EU — see the list below.
Authentication and access
Users sign in with email/password (verification codes via email) or Google OAuth. Authorization for product data is enforced server-side using organization membership and roles. Platform operators may access systems for support and abuse response under internal controls.
AI and customer systems
You bring your own model API keys or endpoints. Inference is performed by those providers under your arrangement with them. Sensitive writes to connected systems can be held for human approval in-product.
Prompt injection and tool output are treated as security issues: least-privilege tools and approval gates matter more than prompt wording alone. Model output is untrusted until a person reviews it.
Subprocessors
We use the following categories of subprocessors. Details may change; material changes will be reflected here.
- Convex — Application database, authentication sessions, and backend functions (European Union (AWS eu-west-1, Ireland))
- Vercel — Web application hosting and edge delivery (European Union (Dublin and Frankfurt); global edge CDN)
- Fly.io — Collaboration sidecar and visual MCP rendering infrastructure (European Union (Frankfurt, fra))
- Stripe — Subscription billing and payment processing (United States / European Economic Area (as applicable))
- Resend — Transactional email (sign-up verification and password reset) (United States)
- Google — Optional sign-in via Google OAuth (when you choose Google) (Global)
- Customer-chosen LLM providers — Model inference using API keys you connect (OpenAI, Anthropic, etc.) (Per your provider contract and region settings)
- Customer-connected systems (MCP) — Architecture, delivery, ITSM, and knowledge sources you connect (Per each system you authorize)
What we do not claim yet
We do not currently claim SOC 2, ISO 27001, a completed third-party penetration test report, or customer-managed encryption keys. We will update this page when that changes. Mid-market buyers who need a DPA can request one at support@aitransformstudio.com.
Security reports
If you believe you have found a vulnerability, email support@aitransformstudio.com with details. Please do not access other customers’ data or disrupt the Service while testing.