Your data, held the waywe'd want ours held.
This page exists because studio owners ask before they connect — and they should. Plain answers, no legalese; the formal versions live in the privacy policy and the terms.
Nothing reaches a member without you
Anything that would touch a member — a win-back, a review reply, a class push — is drafted, queued in your Approvals inbox, and sent only when you say so, from your studio's own email. Control isn't a setting you toggle; it's the workflow itself.
Your credentials, isolated
Each studio's platform credentials are its own — never shared between studios, never sent over email or chat, delivered through a read-once encrypted channel that expires in 48 hours and burns on collection.
Tenant isolation, enforced in the database
Every table that holds studio data carries row-level security from the migration that creates it. A location manager's view is rebuilt server-side per location — the server never sends data the browser is merely expected to hide.
Secrets stay secret
No credentials in code or version control. Automated secret scanning runs on every commit, with a full-history sweep weekly — enforced by machines, not memos.
Backed up, encrypted, nightly
Encrypted backups run every night. Deletion is honored end to end — the data deletion page describes exactly how to ask and what happens when you do.
Your members never log in
Xyzios is staff software. Members have no account, no login, and no exposure — they never see Xyzios at all. And the demo environment used for sales is hard-excluded from every sync and every agent, so no prospect's browsing can ever touch a real studio's data.
Questions this page doesn't answer? Ask directly: hello@xyzios.com — a person who works on the system will answer, not a support tier.