Built for this How it works Who we are Get in touch
How it works

One template. Unlimited recipients.
Each sees their own data.

Iris separates the template from the data. The template — animation, layout, brand — is built once and hosted once. The data is whatever your system already knows. They only meet at view time, in the viewer's browser.

  • You already personalize email, SMS, web, and ads — video has been the one channel that stayed generic.
  • Iris makes video behave like the rest of your stack.
  • One MotionPackage. Any number of recipients. No rendering queue, no pre-generation, no storage.
  • Built API-first, designed to slot into the automation flows you already run.
MOTIONPACKAGE Built once · brand · motion DATA name: "David" rate: "5.24%" renewal: "May 2" From your system · per viewer viewer's browser Hi David, your rate is 5.24% Book advisor → RENDERED LIVE · NOTHING PRE-MADE
Data flow

The video assembles on their device.
Iris never receives their data.

Your system already knows who the viewer is, and hands the data to the player at view time. Two integration shapes — both matching flows you already run.

  • Outbound (email / SMS): Iris API generates a unique URL per contact during campaign send. The viewer clicks, the page loads, the video renders with their data. No data is stored by Iris.
  • Authenticated (portal / app): the viewer is already logged in. Your server pulls from CRM and passes it to the Iris embed at render time. Iris receives nothing.
Two lines of HTML. The player runs in a sandboxed iframe — your security review only needs to permit an iframe. For regulated clients, that's often weeks instead of months.
OUTBOUND — EMAIL / SMS Campaign sends Iris API per contact Unique URL in CTA Contact clicks renders locally nothing stored PAGE GENERATES <200MS · 100K RECIPIENTS IN MINUTES AUTHENTICATED — PORTAL / APP Customer logs in Your server pulls from CRM Embed receives at render time renders locally nothing stored Personal data enters at the browser. It never leaves it. OUTBOUND: non-sensitive values only · AUTHENTICATED: sensitive values stay behind session auth
The architecture guarantee

Your data never reaches our servers.

This is not a privacy policy.
It's what the architecture makes impossible.

Personal data enters at the viewer's browser and never leaves it. Iris delivers a MotionPackage — the animated template — via CDN. Your system injects the viewer's data client-side. Nothing flows back. No PII ever touches Iris infrastructure.

Your compliance team requires no changes to your data governance model. There is no data-sharing agreement to review, because there is no data to share.

Structural guarantee — not a policy claim
Your environment
Client web server (authenticated session)
Browser — viewer data injected locally
Viewer's device — rendering only
Personal data renders locally. Never persisted.
DATA
NEVER
CROSSES
Iris infrastructure
Cloudflare R2 — MotionPackage CDN
Cloudflare Worker — publish, analytics
Analytics — packageId, event, timestamp only
No userData. No PII. No viewer identity. Ever.
For developers & IT teams

Integration concerns?
Let's talk architecture.

Iris is built to pass security reviews in regulated environments. The integration surface is intentionally minimal — an iframe, an API call, and your existing data pipeline. Nothing more.