Tenant isolation
Projects, templates, media and operations are authorized against the owning workspace rather than accepted from a client-provided identifier alone.
An overview of the controls built into JsonCut V2. Detailed procurement material and agreements are provided when the production launch gate is complete.
Projects, templates, media and operations are authorized against the owning workspace rather than accepted from a client-provided identifier alone.
V2 project versions are validated before persistence so an invalid document cannot silently become the next editor state.
Uploads and downloads use scoped references and temporary access where appropriate; project media is not treated as a global public pool.
Custom HTML, CSS and JavaScript run in a restricted project-timed environment with network, storage, navigation and parent access blocked.
The developer API and MCP server expose production workflows, while internal Studio and recovery operations remain private.
Queues, renderer leases, idempotent jobs and storage checks are designed to recover work without duplicating successful outputs.
Contact the JsonCut team for architecture, processing and data-handling questions relevant to your workflow.
Contact security