Full export, whenever you want
A button inside the product exports your software's manifest and all of your data, in a documented format. No permission to request, no ticket to raise, no waiting period.
SECURITY AND REVERSIBILITY
Two questions come up at every first meeting: “what if you disappear?” and “is my data safe?”. Here are the answers, without spin, and what we commit to putting in the contract.
TWO FEARS, ADDRESSED HEAD-ON
Full export at any time, source-code escrow with a third party, reversibility written in black and white into your contract.
Your data and your continuityRoles down to the data level, encrypted secrets, an audit log, hosting in Europe. Compare that with fourteen spreadsheets travelling by email.
What we do, by designYOUR DATA AND YOUR CONTINUITY
Continuity is not a matter of trust: it is a matter of contract. Two clauses, in place from our very first client.
A button inside the product exports your software's manifest and all of your data, in a documented format. No permission to request, no ticket to raise, no waiting period.
The engine's source code is deposited with a third-party escrow agent. We commit to this clause from our first client onwards: if Ghost Studio ceases trading, the code comes to you.
Reversibility is not a sales argument: it is a clause in your contract, naming the export format, the escrow arrangement and the deadline for handing everything over.
The scenario you are worried about, step by step.
The full description of your software — entities, fields, views, roles, automations, indicators — in a readable file. It is the blueprint of your tool: another provider can pick it up.
Every record, its versions, its attachments and your users' roles, in that same export file. Nothing stays with us.
The escrow agent releases the engine's source code under the terms of the contract. Your software can be brought back up on your own hosting.
None of these three points depends on our goodwill at the moment you need them. That is precisely what the clause is for.
EXPORT FORMAT
The export is a single JSON document, readable without Ghost Studio. Its format carries a version number: any breaking change bumps the number, never the content of your earlier exports.
Inside your software, from your account menu: “Export (blueprint + data)”. The same button sits on the preview, in your Ghost Studio workspace. You click it yourself — no support desk involved. Every export is written to the audit log, like any other action.
The format is fully described in the product documentation (docs/EXPORT-FORMAT.md), handed over with the contract: value conventions field by field, and how to recreate the application elsewhere.
Entities, fields, views, roles, automations, indicators, navigation: the complete description of your software.
Every version in order, with the change log and the patch applied at each step.
All of your records, entity by entity, with their identifiers, their dates and their workflow state.
The members of the application and each person's role.
Attachments and their description: name, type, size, originating record.
CYBERSECURITY
No badge, no reassuring acronym: the list of what is actually in place in the product. Your IT team or your IT provider can check it point by point.
Each role sees what it must see, field by field. Anything not explicitly allowed is refused, and the refusal is logged. A record outside your scope is not findable, not merely hidden.
The credentials of your connectors — mail, accounting, ERP — are encrypted in the database. They never travel to your browser, nor to an AI model.
Creations, edits, deletions, reads, exports, permission refusals: everything is timestamped and attributed. You know who did what, and when.
Regular database backups and a restore procedure that is tested, not merely written down. The frequency and the recovery time are set out in the contract.
Your database and your files are hosted in the European Union. No transfer outside the EU in the product's normal operation.
Every file uploaded into your software is scanned before it is stored, and is only served to the roles allowed to read the record it belongs to.
Sign-in by single-use, short-lived link, time-limited sessions, protected cookies. No password ever stored in clear text.
Your data serves your software. It is never sold, never pooled with other clients', never used to train a model.
The question is not “is the risk zero?” — it never is. The question is: compared with what?
SUPPORT
The best architecture protects nothing if habits do not change. Your expert works on this with your teams during the project, not in a memo sent afterwards.
Who sees what, who approves what: the role matrix is written during the scoping phase, with the people concerned, then applied in the software.
Signing in, revoking access when an employee leaves, what to do with a suspicious email: it is part of the training, not an add-on.
An access and role review is scheduled at go-live, then at the rhythm we agree with you. When someone leaves, access is removed the same day.
We display no certification we do not hold, no compliance logo, no invented uptime figure. What you read on this page is what the product does and what the contract says — checkable, point by point, with your IT provider.
We are happy to answer their technical questions, and we hand over the export-format documentation before anything is signed.
Reversibility and escrow are in the contract from the first client onwards.