JsonCut
SECURITY

Creative flexibility.
Deliberate boundaries.

An overview of the controls built into JsonCut V2. Detailed procurement material and agreements are provided when the production launch gate is complete.

01

Tenant isolation

Projects, templates, media and operations are authorized against the owning workspace rather than accepted from a client-provided identifier alone.

02

Validated project writes

V2 project versions are validated before persistence so an invalid document cannot silently become the next editor state.

03

Scoped media access

Uploads and downloads use scoped references and temporary access where appropriate; project media is not treated as a global public pool.

04

Isolated custom code

Custom HTML, CSS and JavaScript run in a restricted project-timed environment with network, storage, navigation and parent access blocked.

05

Minimal public surface

The developer API and MCP server expose production workflows, while internal Studio and recovery operations remain private.

06

Operational recovery

Queues, renderer leases, idempotent jobs and storage checks are designed to recover work without duplicating successful outputs.

Have a security question?

Contact the JsonCut team for architecture, processing and data-handling questions relevant to your workflow.

Contact security