Skip to main content

Security and data protection

How Lenso protects studio and client work.

Lenso keeps product photo jobs private to the studio team and the clients invited to them. This page explains the controls in the product today, where outside services are involved, and what Lenso does not claim.

Last reviewed: August 19, 2026

Access follows the job
  1. Step 1

    Client request

    Email confirmation required

    Products, shot requirements, references, and deadline

  2. Step 2

    Studio review

    Owner or Admin decision

    Nothing becomes a job automatically

  3. Step 3

    Client access

    Email-bound link

    Expires and can be replaced or revoked

  4. Step 4

    Final files

    Private, time-limited access

    Released by the studio

  • Studio access

    Owner, Admin, and Member roles are checked in the backend before protected workspace data is returned or changed.

  • Client access

    Clients enter through email-bound, time-limited links. They do not receive the studio dashboard or use paid studio seats.

  • Private files

    Project files stay in private S3-backed storage and are delivered through time-limited URLs after an access check.

  • Card details

    Stripe handles card entry and payment processing. Lenso does not store full card numbers.

The short version

Lenso uses backend permission checks around studio workspaces, public requests, client access, project data, and file delivery. A public request must be verified before a studio can turn it into a job. Client links expire and can be replaced or revoked. Files stay in private storage and are delivered through limited-time access URLs.

Security is a process, not a badge. This page describes controls supported by the current product and code. It is not a promise of a certification, an uptime level, or a feature Lenso has not earned.

Need a control summary for a client review? Email us with the requirement and we will answer with what Lenso supports today.

Studio access

Studio access stays inside the workspace.

Studio users sign in to a workspace as an Owner, Admin, or Member. Lenso checks the workspace and role in the backend before protected data is returned or changed. Billing and selected account actions use narrower permissions than day-to-day job work.

In production, authenticated sessions use Secure, HttpOnly cookies, short-lived access tokens, rotating refresh tokens, and rate limits on authentication endpoints. Lenso also restricts approved browser origins for authenticated requests.

Read how studio roles and client seats work

Owner
Controls the workspace, billing, team, and account-level actions.
Admin
Helps manage studio work and selected team or request actions without owning the subscription.
Member
Works inside the studio workspace with the permissions and job access assigned by the studio.

Website requests

A request does not become a job by itself.

A client can submit a request from a form linked or embedded on the studio's website. Lenso checks the submission for automated abuse, sends an email confirmation, and keeps conversion disabled until the address is verified.

An Owner or Admin still decides whether to create a job and whether to invite the client. The request never creates a client job or sends a client invitation without that studio action.

Email confirmation proves control of the submitted address. It does not prove the identity, authority, budget, or legitimacy of the requester. The studio still qualifies the work.

Email verified

Request reviewed by the studio

  1. 1. Submitted

    Website form or embed

  2. 2. Email confirmed

    Requester verifies the address

  3. 3. Studio reviews

    Owner or Admin decides

  4. 4. Job created

    Only after studio action

Convert onlyConvert and invite
The studio sees the verified request first, then chooses Convert only or Convert and invite.

Client area

Clients enter through a link, not the studio dashboard.

Clients do not need a Lenso password or a paid studio seat. They open the client area through a link tied to their email and the job. Lenso checks that access before returning project information or files.

The link expires, can be replaced or revoked, and stops working when the job is archived. A client link does not provide access to studio settings, billing, team management, or another studio's workspace.

The client area is Lenso-hosted. Studio name and entitled branding can appear there, but this is not a custom domain or studio-domain email service.

See what the client area includes

Luminance Studios · Thread & Tide

Spring Essentials Refresh

Client email
[email protected]
Access expiration
Time-limited. A new link can replace it.
Rotate linkRevoke portal links
Client access is bound to an email and job, with expiry, rotation, and revoke controls.

Project files

Files are private by default.

Uploaded project files are stored in private Amazon S3-backed storage. Before Lenso returns a file, the backend checks the studio or client access for that job and generates a time-limited URL.

Studios control which proofs are visible to the client and when final files are released. A delivery link is not intended to be a permanent public file address.

HTTPS protects data while it moves between the browser and Lenso. Exact storage region, backup controls, and encryption-at-rest claims depend on the current production environment and are not customer-selectable features today.

Technical details

Lenso supports a presigned direct-upload path, but not every upload path should be described as direct to S3 until the production feature setting and complete upload flow are verified.

TT-SC-LINEN-SHIRT-01_front.jpg

  • Private S3-backed storage
  • Visible to client after studio review
  • Released when the studio chooses
  • Delivered through a time-limited URL
A delivery link is private, checked, and time-limited. It is not a public file address.

Payments

Stripe handles card details.

Lenso uses Stripe for studio subscriptions. When a studio enables client invoicing and connects Stripe, the client can also pay through the studio's connected Stripe account.

Card details are entered and processed by Stripe. Lenso stores the identifiers and payment status needed to show billing state and reconcile the payment. Lenso does not store full card numbers.

Client invoicing and payment are optional. A studio can use Lenso for briefs, review, approval, and final files while keeping its existing accounting or payment process.

Read the Privacy Policy · Read the refunds and disputes policy

Optional AI help

AI suggestions are drafts, not decisions.

AI Brief Assist runs only when the feature is enabled and someone chooses to use it. The text provided for the request and the relevant form structure are sent to the configured AI service to draft suggested fields and follow-up questions.

The suggestions are shown for review. Nothing is applied or saved automatically. A person decides whether to use, edit, or ignore each suggestion.

Lenso does not use studio or client content to train a Lenso-owned model. The Privacy Policy and AI help article describe the data handling that applies when the feature is used.

Read how AI Brief Assist works

Leaving Lenso

Export comes before deletion.

Authorized studio users can request a workspace data export from account settings. Lenso prepares the available workspace data and provides a time-limited download.

Canceling a subscription and deleting an account are separate actions. A deletion request enters a grace period and can be canceled before final execution.

Lenso blocks destructive deletion while active subscriptions, active jobs, open invoices, or unresolved connected-payment obligations remain. This fail-closed behavior is intended to prevent accidental loss while work or financial obligations are still open.

Some records may need to remain for billing, security, fraud prevention, dispute handling, backup cycles, or legal obligations. The Privacy Policy governs the applicable retention and deletion terms.

View account and data terms · Contact support about export or deletion

Outside services

Selected services Lenso uses to operate the product

Lenso relies on specialist providers for storage, email, payments, abuse protection, error monitoring, and optional AI help. This is an operational summary, not a complete legal subprocessor notice. The Privacy Policy is the controlling source for data-handling terms.

Amazon Web Services

Purpose

Private project-file storage and transactional email delivery through S3 and SES.

Data involved

Project files, file metadata, and the delivery information needed to send product emails.

Stripe

Purpose

Studio subscription billing and optional client payments through connected studio accounts.

Data involved

Account and billing metadata, payment identifiers, payment status, and card details entered directly with Stripe.

Cloudflare Turnstile

Purpose

Automated-abuse checks on supported public forms.

Data involved

Browser and network signals needed to evaluate the form submission.

Error monitoring

Purpose

Technical error diagnosis when monitoring is enabled.

Data involved

Error and application context. Default PII sending is disabled, and selected sensitive headers and email-like values are scrubbed before transmission.

Configured AI service

Purpose

Drafting optional AI Brief Assist suggestions when someone chooses to use the feature.

Data involved

The provided request text and relevant form structure needed to create the draft.

Read the Privacy Policy for current data-handling details

Current assurance

What Lenso does not claim today

Lenso will not display a certification badge or enterprise-control claim that it has not earned.

  • Lenso does not currently claim SOC 2 or ISO 27001 certification.
  • Lenso does not currently offer built-in multi-factor authentication.
  • Lenso does not currently offer enterprise SSO or SCIM.
  • Lenso does not currently offer customer-managed encryption keys.
  • Lenso does not currently offer a customer-selected data-residency region.
  • Lenso does not currently promise a public uptime percentage or incident-response SLA.
  • Lenso does not currently operate a public bug bounty.
  • Basic studio branding is not a custom domain or studio-domain email service.

If one of these is a purchasing requirement, ask before starting a pilot. We will explain what is supported today and say clearly when a requirement is not supported.

Reports and incidents

Report a security issue

Email a clear description, the affected URL, steps to reproduce, and a safe way to contact you. Remove passwords, access tokens, client files, and other unnecessary personal information before sending the report.

Do not access or alter data that is not yours, attempt to disrupt the service, run denial-of-service tests, or publish personal information. Lenso does not currently operate a public bug bounty.

[email protected] with the subject Security report

The status page links to a live external feed when one is configured. When it is not, the page says so and directs visitors to support.

Security FAQ

Does a website request create a job automatically?

No. The requester must confirm the submitted email address before the request can be converted. An Owner or Admin at the studio still decides whether to create a job and whether to invite the client.

Does a client need a Lenso password or paid seat?

No. Clients open the client area through an email-bound, time-limited link. Client access does not use a paid studio seat.

Can a studio replace or revoke a client link?

Yes. A studio can send a new link and revoke prior access. Links also expire, and archiving the job closes portal access.

Are project files public?

No. Project files use private S3-backed storage. Lenso checks access before generating a time-limited URL for an authorized studio user or client.

Does Lenso store full card numbers?

No. Card details are entered and processed by Stripe. Lenso stores the identifiers and status needed to operate subscription billing and optional client payments.

Does Lenso use client content to train AI?

Lenso does not use studio or client content to train a Lenso-owned model. AI Brief Assist is optional. When someone uses it, the provided request text and relevant form structure are sent to the configured AI service to create a draft that a person reviews.

Can a studio export and delete its data?

A studio can request a workspace export from account settings. Account deletion is a separate action with a grace period. Active subscriptions, active jobs, open invoices, or unresolved payment obligations can block deletion until they are resolved.

Where is Lenso data stored?

Project files use Amazon S3-backed storage, and application records use PostgreSQL. Lenso does not currently offer a customer-selected data-residency region. Contact security for a current environment summary needed for a client review.

Is Lenso SOC 2 or ISO 27001 certified?

Not currently. Lenso does not display those certification badges. Contact security for the controls and product behavior we can document today.

Does Lenso support multi-factor authentication or enterprise SSO?

Not currently as built-in product controls. Studio access uses password authentication, short-lived sessions, secure cookies, token rotation, role checks, and rate limiting. Do not treat those controls as a substitute for MFA or SSO when either is a purchasing requirement.

How do I report a suspected security issue?

Email [email protected]. Include a clear description, the affected URL, safe reproduction steps, and your contact details. Do not include passwords, access tokens, client files, or unrelated personal information.

Related policies and support

  • Privacy Policy

    How Lenso collects, uses, shares, retains, and deletes personal data.

  • Terms of Service

    The agreement governing studio accounts, subscriptions, client access, and acceptable use.

  • Refunds and disputes

    Subscription, add-on, and studio-client payment responsibilities.

  • System status

    Current service information and incident communication when a live status feed is configured.

  • Contact

    General setup, billing, account, or support questions.

Have a security or procurement question?

Tell us what your studio or client needs to verify. We will answer with the controls we can document today and say clearly when a requirement is not supported.