Open your editor with a code to your work email. No password, no secret in the link.
Sign in with a code, not a password. Three checks stand between the public internet and your site's content, the link we send you carries nothing secret, and a save that fails publishes nothing.
How do I get into my editor?
Pass three checks, in order. The first is an access gate on the editor's own address, edit.trulata.com. It sends a one-time code to your work email and lets you through only when you enter it. The second is a fence on the tunnel that carries that address to our application: it reaches the editor and nothing else. The third is a list inside the application that names, for each site, the verified emails allowed to edit it. Clear all three and the editor shows you your fields. Fail any one and it shows you nothing.
Your dashboard has its own gate. It uses a seat list and a single-use magic link, and its gate and every write path are on their own page. The editor runs on a separate access application with its own guest list, kept apart from the application that guards our internal tools, so a client identity never sits on the list that protects them.
Do I need an account or a password?
No. Enter your work address and a one-time code arrives. Enter the code and you are in. There is no password to choose, store or reset, and we never hold one for you. Your address works only while it is on the editor's guest list, which we maintain for you.
Nothing reaches the application before that step. The editor page, the content it loads and the save endpoint all sit behind the gate, so a request with no sign-in is turned away at the edge and never touches your site's content.

What else can the editor's address reach?
Nothing. The tunnel that connects edit.trulata.com to our application allows one path prefix, the editor's, and answers every other path with not found. A person who has passed the gate is standing in a room with one door: the hostname cannot reach the rest of our application.
Adding a site never loosens the fence. A new site is an entry inside the application plus its editors on the guest list, with no tunnel or DNS work, so the fence stays exactly as it is.
Can another client open my editor?
No. Inside the application, a list names the verified emails that may edit each site. The email it checks is the one the gate verified, carried on the request by the gate itself, never one typed into a form. An address that has passed the gate but is not listed for your site gets a refusal that says why and asks for the address to be added. It does not get a page.
Our own team can open any site we manage, because that is how we help when you ask. That exception is written into the code, not granted by hand.
Is there a secret in the link you send me?
No. Your editor link is a plain address with your site's name in it and nothing else. The page it serves carries no credential either: once you have signed in, your browser sends the gate's own cookie with every request the editor makes, so there is no key to embed and none is embedded. Forward the link and it opens nothing for an address that is not on the guest list.
One per-site key exists, and it stays on the server. It is a break-glass path for our internal tooling: never put in a link, never shared with a client, and useless on its own from outside, because the gate turns the request away before the key is read. The first version of the editor carried a key in the link. We rebuilt it this way, and the old key link now bounces to the gate like any other request.
What happens when I press save?
The save is checked before anything is published. The application keeps a copy of the current content, writes your changes to the site's content file, and re-renders the whole static site from it. If the render fails, the previous content goes back and the response says so: nothing published. If it succeeds, the site redeploys and the editor tells you it will update in about one to two minutes.
Your visitors never download the editor. On our static path the public site stays completely static, with no content system running on it and no editor script on any visitor-facing page. On the WordPress path a save writes into the site's own store and clears its cache. Either way the editor lives on its own address. It runs on a small number of the sites we host today, and what it can and cannot change is its own page.
Every check, in one table.
| Layer | What it checks | When it fails |
|---|---|---|
| Access gate on edit.trulata.com | Who you are, by a one-time code to a listed work email | Request sent to the sign-in gate; the application is never reached |
| Tunnel fence | The path requested is the editor's | Every other path returns not found |
| Site list | The verified email against the site's own list | Refused, with a message to ask for the address to be added |
| Client link | Carries the site name and no secret | A forwarded link opens nothing for an unlisted address |
| Break-glass key | Server-side, internal tooling only | Useless from outside; the gate blocks first |
| Save | The site must render from the new content | Previous content restored, nothing published |
Four requests sent from the public internet with no sign-in, the plain link, the old link with a key in it, the key sent as a header and a forged email header, all landed on the sign-in gate, and that result is in the editor's setup record.
Questions, answered.
Do I need a password for the editor?
No. Enter your work address, a one-time code arrives, and you enter the code. We never hold a password for you.
Can I forward the editor link to a colleague?
Yes, and it opens nothing for them until their address is on the editor's guest list and listed for your site. Ask us to add them and it works.
Can another client see or edit my site?
No. Each site has its own list of verified emails. An address not listed for your site is refused, and the refusal says why.
What happens if a save fails?
Nothing is published. The previous content is restored and the editor tells you the render failed instead of deploying a broken page.
Does the editor slow my website down?
No. The editor runs on its own address and adds nothing to a visitor's page load. On our static path the public site stays fully static with no content system on it.
Is this the same login as my dashboard?
No. The dashboard uses a seat list and a single-use magic link. The editor has its own gate with its own guest list and a one-time code, kept apart on purpose.
See it running
before you decide.
The demo is the real product on a fictional company, with no form in front of it. Pricing is three published tiers. Setup on your own accounts takes two to four weeks.
Open the live demo See pricing
New here? See what the Command Center is. Prefer to write? Send us the one thing you want to know.
- Refreshed when you open itLive data on page load, never a monthly PDF
- Counted from your own formsLeads recorded server-side, compared daily with Ads and GA4
- Four answer engines, measuredChatGPT, Gemini, Claude and Grok, with a published denominator
- A review-first queue on every sendEvery draft waits in a review-first queue and every send is logged.