Trust

Local-first drone media, protected account access.

Sightlock is being built as a professional desktop app and repository layer for organisation-wide drone media archives. Subscription licensing verifies entitlement without turning every customer archive into a cloud upload.

Sightlock repository manager with project cards and live map preview
Repository posture

Drone media stays in the operator's project folders.

The product positioning is local-first: Sightlock indexes and remembers geometry, thumbnails, telemetry metadata, missing-file state, and project context for desktop workflows rather than uploading entire drone archives by default.

Subscription access

Licences are account-owned and machine-bound.

The launch model is first month free, then NZD $30/month for one active workstation and NZD $25/month for each additional active workstation. One account licence key covers the paid device allowance, with customer-managed deactivation and support-assisted resets for genuine hardware changes.

No-card trial

Free trials should be easy, but not abusable.

Customers can start without payment information. The signup path is designed to require email delivery, anti-abuse checks, and machine-trial memory before real public key creation opens.

Protected dashboard

Account and owner dashboards stay behind login.

Public product pages stay crawlable for customers and search engines. Customer billing, machine bindings, licence keys, owner reports, and support data stay behind authenticated APIs.

Operational support

Support should focus on activation, media sources, and recovery.

Useful support paths include machine reset, checkout/billing help, failed imports, missing media, telemetry source review, export issues, and repository setup for teams with shared folders.

Release discipline

Installers should be versioned, signed, hashed, gated, and rollback-ready.

The public download path is intentionally protected until the app lane proves code signing, manifest integrity, checksum proof, update channels, and rollback behaviour.

Account, email, and protection model

Surface Launch approach
Public website Open, crawlable marketing/docs/demo pages with structured metadata, sitemap, and AI-readable product briefing.
Customer account Protected sign-in for licence key, billing portal, active-device allowance, bound machines, trial status, and subscription state.
Owner dashboard Admin-only view for customers, trials, subscriptions, payment issues, machine bindings, attribution, and support history.
Human inboxes Microsoft 365 mailboxes for real conversations from addresses such as enquiry@sightlock.co.nz and oliver@sightlock.co.nz.
Automated email Transactional licence-key, trial-reminder, expiry, and billing emails sent through a dedicated email delivery service.
Abuse protection Public signup and account APIs are designed for anti-abuse checks, rate limits, signed webhooks, and no-card trial machine memory.
Release workflow Beta and stable channels, protected downloads, manifest proof, SHA256 checksums, and rollback process documented before public installer launch.

Launch trust checklist

Area Expected launch position
Media storage Local project folders remain the source of truth. Cloud services are for subscription/account state unless a future cloud sync feature is deliberately added.
Billing Stripe subscriptions with first-month trial, one account licence, and discounted additional active workstations.
Entitlement Supabase-backed subscription, account licence, device allowance, client-safe entitlement payloads, and machine binding in the desktop app.
Installer Signed Windows installer, release manifest, SHA256 hash, and public download only after release preflight passes.
Security contact Public vulnerability and support contact is published at /security/, with responsible disclosure guidance.
Privacy and terms Reviewed privacy, terms, refund/cancellation, cookie/analytics, and support language before paid launch.

Release workflow

Beta/stable channels, installer manifests, checksums, rollback, and code-signing plan.

View release workflow

Cookie and analytics note

Essential storage, Turnstile/security signals, attribution, and future analytics disclosures.

Read cookie note

Security contact

How to report vulnerabilities, account issues, and protected-download problems.

Open security page