Trust

Genuine permissions.
Honest sharing. Boring encryption.

Security you don't have to think about — designed so the safe path is also the easy path. The most dangerous thing in most studios is the workaround, so we removed the reasons to need one.

Permissions

A permission model with three layers.

Most storage bolts sharing on afterwards, and it shows. Stone was built around three kinds of "who may do what" — and they answer together.

Roles, for the organization

Who you are in the company. Admins run the place, members do the work, guests see exactly what they're shown and nothing else. Roles settle the big questions once, so individual folders don't have to keep re-asking them.

Access control, on the tree

Folders carry real, inheritable permissions that behave the way filesystems should — set at the top, respected all the way down, cut off cleanly where you say. Under the hood they're NFSv4-style ACLs, surfaced as Windows DACLs and macOS permissions — one rule, enforced identically on every platform and every client, because a rule that depends on which app you opened isn't a rule.

Capability links, for the moment

A share link is a permission — not a loophole around one. Scoped to a path, as narrow as you like, expiring when you say, revocable the second you change your mind. The link stops working; you don't chase down who forwarded it.

All three meet at every single request. Not at sync time, not at the office door — at the request. Change the answer and the access changes with it, everywhere, immediately.

Cross-company

Share across companies without exporting.

Grant another studio's people access to a folder and it appears inside their own filespace — mounted, browsable, live. No transfer portal, no second copy quietly drifting out of date, no "final_v3" arriving by courier.

Nothing leaves. The bedrock still counts every chunk once, so a folder shared with three studios costs nobody three times. Revoke the grant and it's gone from every mount, everywhere, instantly.

And every grant — created, exercised, revoked — lands in the audit log with a name and a timestamp. Trust, with receipts.

terminal
$ stone share ~/Stone/S02_Delivery --with colorworks.no \
    --until 2026-09-01 --read-only
 granted — visible in their mount now · revocable · audited
   # no export, no upload bar, no "which version is this" email
Encryption

Encryption at rest. And everywhere else.

Good encryption is like good plumbing — you notice it exactly never. Here's what's under the floor.

In transit

Everything moving between your machines and Stone travels encrypted — file contents, names, notifications, all of it. There is no unencrypted mode to misconfigure.

At rest

Every chunk in the bedrock is encrypted before it touches a disk, and each customer's data is cryptographically isolated from every other customer's. Shared infrastructure, separate locks.

Keys, rotated

Keys rotate on a schedule and on demand — quietly, without downtime, without you filing a ticket. On Enterprise, you can hold them yourself: customer-managed keys, so access can be cut at the source, by you.

Your bucket, same rules

With BYO bucket, your bytes live in your storage account, under your name and your jurisdiction — with the same encryption, the same isolation, the same rotation. Stone runs everything above it.

One claim we won't make: "zero-knowledge." A system that deduplicates, shares and rewinds your work has to be able to operate on it, and pretending otherwise is marketing. What we promise is plainer and more useful — encrypted everywhere, isolated per customer, keys rotated, every access accountable, and on Enterprise, keys you hold yourself.

Immutability

Ransomware can encrypt tomorrow.
It can't encrypt yesterday.

Chunks are immutable — a change writes new chunks, it never rewrites old ones. Add full history and the arithmetic is simple: an attacker, a bad script, or an ordinary Tuesday can only ever damage the present. Pick a nanosecond before things went wrong, and rewind.

How infinite history works →

Compliance

Audited by professional skeptics.

ISO/IEC 27001Information security management
SOC 2 Type IISecurity · availability · confidentiality
HIPAAHealthcare-grade data handling
TPNTrusted Partner Network — media & entertainment

Audit reports available under NDA — contact@stone.no. More on our program at compliance.

Responsible disclosure: we'd love to give you a security@stone.no, but we run exactly two mailboxes and that isn't one of them. Send findings to contact@stone.no with "security" in the subject — it gets read first, and we answer fast.

Safe enough to forget about.

Start a free 200 GB filespace and share something with someone you'd normally email a link to.