Security you don't have to think about — designed so the safe path is also the easy path. The most dangerous thing in most studios is the workaround, so we removed the reasons to need one.
Most storage bolts sharing on afterwards, and it shows. Stone was built around three kinds of "who may do what" — and they answer together.
Who you are in the company. Admins run the place, members do the work, guests see exactly what they're shown and nothing else. Roles settle the big questions once, so individual folders don't have to keep re-asking them.
Folders carry real, inheritable permissions that behave the way filesystems should — set at the top, respected all the way down, cut off cleanly where you say. Under the hood they're NFSv4-style ACLs, surfaced as Windows DACLs and macOS permissions — one rule, enforced identically on every platform and every client, because a rule that depends on which app you opened isn't a rule.
A share link is a permission — not a loophole around one. Scoped to a path, as narrow as you like, expiring when you say, revocable the second you change your mind. The link stops working; you don't chase down who forwarded it.
All three meet at every single request. Not at sync time, not at the office door — at the request. Change the answer and the access changes with it, everywhere, immediately.
Grant another studio's people access to a folder and it appears inside their own filespace — mounted, browsable, live. No transfer portal, no second copy quietly drifting out of date, no "final_v3" arriving by courier.
Nothing leaves. The bedrock still counts every chunk once, so a folder shared with three studios costs nobody three times. Revoke the grant and it's gone from every mount, everywhere, instantly.
And every grant — created, exercised, revoked — lands in the audit log with a name and a timestamp. Trust, with receipts.
$ stone share ~/Stone/S02_Delivery --with colorworks.no \ --until 2026-09-01 --read-only ✓ granted — visible in their mount now · revocable · audited # no export, no upload bar, no "which version is this" email
Good encryption is like good plumbing — you notice it exactly never. Here's what's under the floor.
Everything moving between your machines and Stone travels encrypted — file contents, names, notifications, all of it. There is no unencrypted mode to misconfigure.
Every chunk in the bedrock is encrypted before it touches a disk, and each customer's data is cryptographically isolated from every other customer's. Shared infrastructure, separate locks.
Keys rotate on a schedule and on demand — quietly, without downtime, without you filing a ticket. On Enterprise, you can hold them yourself: customer-managed keys, so access can be cut at the source, by you.
With BYO bucket, your bytes live in your storage account, under your name and your jurisdiction — with the same encryption, the same isolation, the same rotation. Stone runs everything above it.
One claim we won't make: "zero-knowledge." A system that deduplicates, shares and rewinds your work has to be able to operate on it, and pretending otherwise is marketing. What we promise is plainer and more useful — encrypted everywhere, isolated per customer, keys rotated, every access accountable, and on Enterprise, keys you hold yourself.
Chunks are immutable — a change writes new chunks, it never rewrites old ones. Add full history and the arithmetic is simple: an attacker, a bad script, or an ordinary Tuesday can only ever damage the present. Pick a nanosecond before things went wrong, and rewind.
Audit reports available under NDA — contact@stone.no. More on our program at compliance.
Responsible disclosure: we'd love to give you a security@stone.no, but we run exactly two mailboxes and that isn't one of them. Send findings to contact@stone.no with "security" in the subject — it gets read first, and we answer fast.
Start a free 200 GB filespace and share something with someone you'd normally email a link to.