Workspace FAQ
Short answers about pricing, security, and how the workspace works.
What am I actually paying for?
Two line items: $45 one-time for a 500-sticker Industrial Lab Roll (physical goods, shipped to you), and $15/month for the Secure Workspace (audit log, saved templates, multi-QR mapping, Excel export, unlimited seats within your corporate domain).
Can I use this for HIPAA-covered PHI, clinical trials, or classified data?
No. Workspace is in beta and does not yet carry SOC 2, HIPAA, ISO 27001, PCI, FedRAMP, or 21 CFR Part 11 attestations. The Terms explicitly prohibit storing PHI, payment card data, ITAR-controlled data, classified information, or clinical-trial records. Use it for non-regulated internal asset tracking: lab inventory, equipment calibration logs, inspection checklists, R&D materials, and similar. See our compliance roadmap.
How does the domain lock work?
When you sign up, we look at your email domain (e.g. @novartis.com). The first user on that domain becomes the org admin. Every subsequent signup on the same domain arrives as pending until the admin approves them. Free email providers (Gmail, Outlook, Yahoo, etc.) can't anchor an org.
What ends up in the audit log?
Every create, update, view, archive, and membership action, with timestamp, user, IP address, and object ID. The rows are enforced append-only at the database level with a Postgres trigger that raises an exception on UPDATE or DELETE.
Why archive instead of delete?
Regulated inspection cycles typically expect historical data to remain queryable. Assets you 'delete' are marked archived and hidden from default views, but stay in the database and the audit log. This aligns with common retention-friendly practice.
What happens if I cancel the Secure Workspace?
Your data stays in the database. The workspace becomes read-only, existing scans still resolve, existing exports still work, but you can't create or edit new assets. Resubscribe any time to unlock writes again.
Do you support SSO / SAML?
Google Workspace sign-in is available today. Full SAML/OIDC SSO is on the compliance roadmap alongside SOC 2 Type II. If you need it sooner for a paid pilot, email hello@stickylink.io.
How do the physical stickers work?
Each roll ships with a unique 6-letter batch code printed on the first sticker. Your org admin enters that batch code once and all 500 stickers in the roll auto-claim to your workspace. Then any member can assign individual stickers to assets or templates.
Can multiple stickers point to the same asset?
Yes, that's the multi-QR mapping feature. Assign as many stickers as you want to a single asset (e.g. 20 different equipment locations all pointing to one 'Autoclave #2' record). Every scan resolves to the same dynamic page and logs the read event.
