Security Overview & Trust Statement
Version draft-2026-10-03
Version: 1.0Effective Date: [Date To Be Added]
This RestoreIQ Security Overview & Trust Statement (this “Security Statement”) describes the security, privacy, trust, and operational principles used by Pelagic Studio LLC, a Louisiana limited liability company (“Pelagic Studio,” “we,” “us,” or “our”), in connection with RestoreIQ.
This Security Statement is intended to provide customers, trial users, partners, advisors, investors, and prospective customers with a practical overview of RestoreIQ’s security posture. It is not intended to create warranties, service level commitments, insurance obligations, compliance certifications, or guarantees unless expressly stated in a separate written agreement.
1. Security Philosophy
RestoreIQ is designed to help customers organize, document, and manage restoration projects, including project records, media, inventory, purchase records, vendors, budgets, schedules, guided workflows, reports, exports, and Book Studio materials.
Pelagic Studio’s security approach is based on the following principles:
protect customer accounts and project data;
collect only information reasonably needed to operate RestoreIQ;
use reputable third-party providers where appropriate;
apply reasonable access controls;
separate customer-facing access from administrative access;
support customer export and backup practices;
treat uploaded media and project records as customer-controlled content;
provide clear disclosures about AI, exports, third-party services, and retention;
improve security practices as RestoreIQ matures; and
communicate transparently about material security and trust practices.
2. Data Types Protected
RestoreIQ may store or process several categories of customer information, including:
account information;
subscription and billing status information;
project records;
vehicle records;
assembly and part records;
vendor and purchase records;
budget and expense records;
schedule information;
restoration workflow information;
uploaded photos, scans, receipts, and documents;
captions, narratives, and AI-generated content;
PDF exports, documentation packages, and Book Studio materials;
support communications;
usage and diagnostic logs; and
security and authentication events.
Customer Content belongs to the customer, subject to the limited rights needed for Pelagic Studio to operate RestoreIQ under the Terms of Service / SaaS Access Agreement.
3. Account Security
RestoreIQ may use authentication providers and account security controls to help protect access to customer accounts.
Depending on the product configuration and plan, account security may include:
password-based authentication;
passwordless authentication;
third-party authentication providers;
session management;
role-based access controls;
administrator and user role distinctions;
multifactor authentication, if offered;
single sign-on, if offered;
account verification workflows;
suspicious login monitoring; and
access revocation.
Customers are responsible for maintaining the security of their credentials, devices, browsers, local files, and authorized users.
4. Access Controls
Pelagic Studio aims to limit access to customer information to people and systems that need access for legitimate business, operational, security, support, or legal purposes.
Administrative access, where available, should be limited to authorized personnel and used only for appropriate purposes such as:
support;
troubleshooting;
security review;
billing/account administration;
system maintenance;
incident response;
legal compliance; and
product improvement.
Customer-side access is controlled by account configuration, roles, authentication, and subscription permissions.
5. Cloud Hosting and Infrastructure
If RestoreIQ is offered as a cloud-hosted service, it may be hosted using reputable cloud, deployment, database, authentication, storage, monitoring, and infrastructure providers.
Cloud infrastructure may provide capabilities such as:
managed hosting;
network security controls;
encrypted connections;
application deployment controls;
logging and monitoring;
database services;
storage services;
backup capabilities;
availability tooling; and
security updates.
Specific vendors may change over time as RestoreIQ evolves.
6. Local Version Security
If RestoreIQ is offered as a Local Version, customer-controlled security becomes especially important.
For local installations or local browser-based deployments, customers may be responsible for:
device security;
operating system updates;
local database protection;
file system permissions;
local media storage;
backups;
cloud-sync folder configuration;
encryption of local drives;
account access on shared computers;
antivirus or endpoint protection;
network security;
physical device security; and
data recovery after device loss, failure, deletion, corruption, or malware.
Pelagic Studio may provide guidance or features to assist with backups and exports, but customers remain responsible for local data protection unless otherwise agreed in writing.
7. Encryption
RestoreIQ is intended to use reasonable encryption practices appropriate to the product configuration.
Depending on the version and implementation, this may include:
encryption in transit using HTTPS/TLS for cloud services;
encryption at rest by hosting, database, or storage providers where supported;
local device encryption where enabled by the customer;
encrypted authentication flows where supported by providers;
secure handling of payment data through third-party payment processors; and
protection of sensitive credentials and secrets through environment variables or secure configuration practices.
Customers using a Local Version should enable operating-system or device-level encryption where appropriate.
8. Payment Security
If RestoreIQ uses a third-party payment processor, payment card information may be processed by that provider.
Pelagic Studio does not intend to directly store full credit card numbers when using a third-party payment processor. Payment processors may maintain their own security controls, certifications, terms, and privacy practices.
Customers should review the applicable payment processor’s terms and privacy disclosures where relevant.
9. AI Security and Data Handling
RestoreIQ may offer AI-assisted features such as captions, narratives, summaries, recommendations, project insights, media organization, documentation assistance, and guided workflow suggestions.
Depending on configuration, AI processing may occur through:
manual-only mode;
local AI mode;
cloud AI mode;
third-party AI providers; or
hybrid approaches.
Pelagic Studio’s AI trust principles include:
giving customers reasonable notice when AI features are used;
making clear that AI output may be inaccurate or incomplete;
encouraging customers to review and verify AI outputs;
avoiding use of AI as a substitute for professional mechanical, safety, legal, insurance, or regulatory advice;
limiting AI processing to selected or necessary project context where feasible; and
providing additional AI disclosures as features mature.
Customers are responsible for selecting AI settings appropriate for their privacy, security, and risk preferences.
10. Media and File Handling
RestoreIQ may process photos, videos, scans, receipts, PDFs, and other uploaded files.
Customers should understand that media files may contain embedded metadata such as:
file names;
date and time;
camera details;
device details;
location metadata, if enabled by the source device;
image resolution;
document metadata; and
editing history.
Customers are responsible for reviewing files and removing metadata they do not want to upload, store, export, print, or share.
11. Backups and Recovery
Pelagic Studio may maintain backups for cloud-hosted RestoreIQ systems according to then-current operational practices.
Backups are primarily intended for operational continuity and disaster recovery. They may not support customer-specific point-in-time restoration, restoration of individually deleted files, or recovery from every loss event.
Customers are responsible for maintaining independent backups of important project records, media, receipts, book files, exports, and final documentation.
For Local Versions, customers are responsible for their own backup configuration and recovery.
12. Logging and Monitoring
RestoreIQ may use logs and monitoring tools to support:
reliability;
performance;
troubleshooting;
fraud prevention;
abuse detection;
security monitoring;
support diagnostics;
product improvement; and
incident response.
Logs may include technical information such as IP addresses, device information, browser information, access times, error messages, feature usage, account identifiers, and security events.
13. Vulnerability Management
Pelagic Studio intends to address security vulnerabilities using commercially reasonable practices appropriate to RestoreIQ’s stage, architecture, risk profile, and available resources.
Security practices may include:
dependency updates;
framework updates;
review of security advisories;
remediation of known vulnerabilities;
access control review;
configuration review;
secure coding practices;
backup and recovery review;
logging and monitoring review; and
customer communication where appropriate.
14. Incident Response
If Pelagic Studio becomes aware of a security incident affecting RestoreIQ, it will evaluate the incident and take reasonable steps appropriate to the nature and scope of the issue.
Incident response may include:
investigation;
containment;
remediation;
service provider coordination;
customer communication;
password or credential reset recommendations;
legal review;
notification to affected parties where required by law; and
post-incident improvement activities.
Not every security event is a reportable data breach. Notification obligations depend on applicable law, the type of information involved, and the facts of the incident.
15. Third-Party Vendor Oversight
RestoreIQ may depend on third-party vendors for authentication, hosting, payments, AI processing, analytics, support, logging, monitoring, storage, email, print workflows, and other services.
Pelagic Studio aims to use reputable vendors and review provider capabilities appropriate to RestoreIQ’s stage and risk profile.
Third-party services may have their own security controls, certifications, availability, limitations, terms, privacy policies, subprocessors, and incident response practices.
16. Customer Responsibilities
Security is shared between Pelagic Studio and customers.
Customers are responsible for:
using strong passwords or secure authentication methods;
protecting account credentials;
enabling multifactor authentication where available;
limiting account access to trusted users;
removing users who no longer need access;
securing local devices;
maintaining local backups;
protecting exported files;
avoiding upload of unnecessary sensitive information;
reviewing AI outputs before use;
reviewing exported and printed materials before distribution;
complying with applicable laws; and
promptly reporting suspected unauthorized access.
17. Confidentiality and Internal Handling
Pelagic Studio treats non-public customer information as confidential and intends to use customer information only for legitimate business, operational, support, legal, security, and product purposes as described in applicable policies and agreements.
Access to customer information should be limited to authorized persons and service providers who need access for legitimate purposes.
18. Data Minimization
Pelagic Studio aims to collect and process information reasonably needed to provide RestoreIQ, operate the business, improve the product, maintain security, provide support, process subscriptions, and comply with law.
Customers should avoid uploading unnecessary sensitive personal information, regulated data, or unrelated files.
19. Compliance Posture
RestoreIQ is intended as a vehicle restoration project organization, documentation, media management, workflow, export, and Book Studio tool.
Unless expressly stated in a separate written agreement, RestoreIQ is not designed, certified, or audited for specialized regulated environments such as:
HIPAA-regulated health data;
PCI DSS cardholder data storage by Pelagic Studio;
government classified information;
CJIS data;
ITAR-controlled technical data;
safety-critical systems;
automotive roadworthiness certification;
insurance certification;
legal compliance certification; or
professional engineering certification.
Customers must not use RestoreIQ for regulated data or regulated purposes unless Pelagic Studio has expressly agreed in writing.
20. Security Roadmap
As RestoreIQ matures, Pelagic Studio may consider additional trust and security enhancements, such as:
formal security policies;
expanded role-based access controls;
enhanced audit logs;
customer-controlled exports;
stronger backup controls;
improved data retention controls;
formal vendor review;
security questionnaires;
vulnerability disclosure process;
incident response procedures;
penetration testing; and
additional compliance documentation.
Availability and timing of these enhancements will depend on product maturity, customer needs, risk profile, and business priorities.
21. Reporting Security Concerns
Customers, researchers, partners, and users may report suspected security issues to Pelagic Studio.
Security contact:
Pelagic Studio LLC[Business Address To Be Added][City, State ZIP To Be Added]Attn: Rickey L. Ferand, President, OwnerEmail: [Security Contact Email To Be Added]
Reports should include:
description of the issue;
affected feature or URL;
steps to reproduce, if safe and appropriate;
screenshots or logs, if available;
account email, if relevant; and
contact information for follow-up.
Do not access, modify, delete, download, or disclose customer data without authorization.
22. No Guarantee
Pelagic Studio uses reasonable efforts to protect RestoreIQ, but no software, hosting environment, transmission method, storage system, device, network, authentication system, AI provider, payment processor, or backup process is completely secure or error-free.
This Security Statement is informational and does not create warranties, guarantees, service level commitments, or obligations beyond those expressly stated in a signed written agreement or applicable law.
23. Changes to This Security Statement
Pelagic Studio may update this Security Statement from time to time as RestoreIQ evolves.
Updated versions may be posted on the website, presented in the application, emailed, or otherwise made available through reasonable means.
24. Contact
Questions about this Security Statement may be directed to:
Pelagic Studio LLC[Business Address To Be Added][City, State ZIP To Be Added]Attn: Rickey L. Ferand, President, OwnerEmail: [Security Contact Email To Be Added]