ASH.STUDIO
Trust

Security

Effective August 4, 2026

Your salon runs on client trust. ASH.STUDIO runs on protecting that trust for you. This page is our honest posture on how we handle security today — not marketing gloss.

Encryption

  • In transit: All connections to ASH.STUDIO use TLS 1.2 or higher. HTTP requests are redirected to HTTPS.
  • At rest: Database and file storage are encrypted at rest using industry-standard AES-256 encryption managed by our cloud providers.
  • Secrets: API keys, tokens, and other credentials are stored as encrypted environment variables. Engineers cannot read production secrets in plaintext.

Tenant isolation

Every salon on ASH.STUDIO is a separate tenant in our database. Every query — every read and every write — is scoped by tenant ID at the application layer. A stylist on one salon’s account cannot see any data from another salon’s account, ever.

Authentication

  • Authentication is handled by Clerk, an industry-standard identity provider trusted by thousands of SaaS companies.
  • Passwords are never stored by us — Clerk hashes and stores them using bcrypt with per-user salts.
  • Google Single Sign-On is supported. Multi-factor authentication is available on all accounts.
  • Sessions expire automatically. Suspicious sign-in attempts trigger additional verification.

Payment security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified processor. ASH.STUDIO never sees, stores, or transmits full credit card numbers. Card data is tokenized by Stripe before ever reaching our servers.

Infrastructure

  • Hosting: Vercel edge network, with automatic DDoS mitigation and web application firewall.
  • Database: Neon-managed Postgres with automated daily backups, point-in-time recovery, and geo-redundant storage.
  • Region: Primary infrastructure runs in U.S. East.

Access controls

  • Engineering access to production data is limited to a small number of authorized personnel and is logged.
  • Support access to a salon’s account requires the salon owner’s explicit permission for each session.
  • We use least-privilege API scopes for every third-party integration (Stripe, Twilio, Resend, Phorest, and any others).

Monitoring and incident response

We monitor application logs, error rates, and unusual traffic patterns continuously. If we detect a security incident that could affect your data, we’ll notify you within 72 hours of confirming the issue and share what we know, what we’re doing, and what you can do.

Data portability and deletion

You can export your salon data any time from your account. If you cancel, we retain your data for 30 days — long enough to reactivate if you change your mind — then permanently delete it. Backups are purged on a 35-day rolling window.

Third-party sub-processors

The services we rely on to run ASH.STUDIO are named in our Privacy Policy. Each is bound by industry contract terms limiting how they can process the data we send them.

What we’re building toward

ASH.STUDIO is a young platform. We’re not SOC 2 certified yet, and we’re not going to pretend otherwise. Formal third-party attestation is on our roadmap as the customer base grows. In the meantime, we run on the same principles those audits measure: least privilege, encryption everywhere, monitored access, and honest incident response.

Reporting a security issue

If you believe you’ve found a vulnerability, please email hello@ash.studio with the details. We’ll acknowledge within one business day and work with you to resolve it.

Questions

ASH Studios, LLC · Salt Lake City, Utah · hello@ash.studio