Skip to content
Your record. Your knowledge. Your business model.Read the argument →
Sovereignty

The record is yours.

Open formats on your own storage, with an open core underneath. The model proposes and your record decides.

Request a Demo
The fundamentals

What sovereignty means here.

Four commitments that hold no matter how you deploy.

Your infrastructure

The record sits on storage you control. It is yours, never a tenancy inside our product.

Your jurisdiction

Where the data lives is a decision you make, not a consequence of which vendor you picked.

No lock-in

Open formats and an open core. You can read your files without our software, and leaving costs you nothing but the tooling.

Your choice of model

The model proposes and never decides, so which one you use, and where it runs, is yours to set.

Open source

The open core.

The foundation is open and public. It is the BIM Open Toolkit, created by Christopher Diggins at Ara 3D and released under the MIT licence. What studio 2.5 adds is the harness that reaches the record and the environment that runs agents against it.

BIM Open Toolkit

The hub of the family and the analyst application. Node packs that know about buildings, samples over real models and headless checks.

MIT licence

BIM Open Schema

The specification. A building model as Parquet tables, one addressable element per row, each carrying an identity that survives the file.

MIT licence

BIM Open Data

Reads and writes BIM Open Schema and IFC in .NET, builds meshes and converts models to DuckDB.

MIT licence

BIM Open Flow

Graphs over tables. A dataflow engine, node packs, a headless host, a web editor and an MCP server.

MIT licence

BIM Open Viewer

A WebGL viewer for large building models, running in the browser.

MIT licence

BIM Open Notebook

A session with an agent, kept as a document of results that can be evaluated again.

MIT licence

OpenThe BIM Open Toolkit: Schema, Data, Flow, Viewer and Notebook. Public, and a graph you build on the canvas is yours whether or not you work with us.
OursThe tools that reach your record, and the environment that runs agents against it at scale, under governance, with everything they decide written down.
YoursEverything that accumulates. The record and the determinations, with the evidence and the signatures attached. On your storage, in open formats, and nothing we can take back.
Storage

Where the record actually lives.

Markdown for the determinations, Parquet for everything else. Both sit on your storage and any query engine reads them. If you stopped working with studio 2.5 tomorrow, you would open your record the same afternoon.

Answers

Where the answers come from.

Everything a model produces here is a proposal. The facts underneath it come from defined tools reading your record rather than from the model's memory, so an answer can be traced. In compliance work the line is harder still, and a rule engine issues the verdict.

Lock-in

What lock-in costs you.

The record sits on your storage in open formats. Leaving is not a project.

What leaving costs on a typical platform, compared with leaving studio 2.5, across four measures
Leaving a typical platformLeaving studio 2.5
Where the record isIn the vendor's tenancyYou request an export and waitAlready on your storageNothing to request
What you get backA flattened export, structure lostRelationships between records do not surviveExactly what was thereParquet and markdown, structure intact
What opens itTheir software, or a conversion projectOften a proprietary schemaDuckDB, pandas, Polars, Excel through Power Query, a text editorOpen standards, published schema
The decisions and evidenceOften not exportableComment threads, approvals, attachmentsPlain text files, one per determinationReadable without any tooling
Data protection

Security.

Your record stays on your systems. Most security questions about a platform are questions about where the data went, and here the answer is that it did not go anywhere.

Inside your boundary: The record: Parquet and markdown on storage you control; The gateway: The tools that read the record and return what it holds; The agent environment: Runs where you run it, under your access control; The determinations: Written back, append only, never leaving. Outside: A language model: Proposes. It has no authority to issue a verdict; Interchangeable: Hosted, private, or your own weights; Holds nothing: No index of your record is built or kept outside.

Common security review questions and studio 2.5’s answers
What a security review asksThe answer
Where does our data physically reside?On your storage, in your jurisdiction.We do not choose it and we do not host it.
Do you hold a copy of our record?No.There is no tenancy of your data inside our product.
Is the model provider retaining anything?Your choice of provider and terms.The model is interchangeable, so this is a procurement decision you keep.
Can an agent act without a person?Only where you have said it may.What requires a signature is set by you and recorded.
What happens to the record if we stop?Nothing.It is already yours, already readable, already where it lives.
Over time

This is how you get smarter.

Everything your people decide gets kept, and it accumulates. After ten years the record holds things nobody in the organization ever knew on their own. That only works if the record is yours, because the value is in what has built up rather than in the software reading it.

Ask the hard questions.

Deployment, residency, access, and what leaves your environment. Bring the list.