Cleaner security boundary
No Fly.io tokens, model keys, user files, or workspace state belong in the public landing repo.
The public site stays at sophosai.app. The authenticated product will live at studio.sophosai.app: user accounts, personal workspaces, protected Workspace Shell, and Fly.io-backed workspace runtimes.
No Fly.io tokens, model keys, user files, or workspace state belong in the public landing repo.
Visitors can understand SophosAI publicly, then launch into a separate logged-in Studio when ready.
When Studio auth is ready, this page can redirect or the Launch Studio CTA can point to the app subdomain.