Internal · not for Jessica

GetEYT — the plan

Three lists, a straight answer on texting, and where the servers stand now that both are live and running the platform.

The servers, live

Both boxes arrived on the 28th and the platform is running on both of them. This section is what changed, what it cost to find out, and the one thing still standing between it and a working web address.

ProductionStaging
Address151.247.172.55151.247.172.56
Size3 processors, 16 GB, 196 GB1 processor, 4 GB, 49 GB
ServicesAll four up, app reporting healthyAll four up
Data loaded8 studios, 162 clients, 2,371 bookings, 5 cohortsThe same
Way inOne key, held only on your Mac. Passwords are switched off on both

Locked down before anything was installed

Backups are real, and they have actually been restored

Production copies its whole database to the staging server every night. Different building, so a fire in one does not take both. Then it was restored there for real, not assumed: 98 tables, 8 studios, 162 clients, 2,371 bookings, 5 cohorts, matching production exactly. That restore repeats itself every Sunday and shouts if it ever stops matching.

This is the interim arrangement. The permanent one puts the backup with an outside storage provider, which is the R2 line below.

Live on the internet, with real certificates

  • https://app.netryse.com — production
  • https://staging.netryse.com — staging, ours, never shown to anyone

Both certificates issued automatically and renew themselves. Plain http redirects to https. When Jessica settles the address on the call, app.geteyt.com gets added alongside rather than swapped in, so there is no cutover and nothing breaks.

What Cloudflare and R2 actually are, since you asked

  • Cloudflare sits in front of the server. Every visitor reaches it first, so the server's real address never appears in public, bad traffic is filtered before it arrives, and an attack aimed at the site hits them instead of a $150 box. Free.
  • R2 is their file storage, in the same account. Two jobs here: holding student video uploads and certificates, and holding the nightly database backup somewhere that is not the server.
  • Why R2 and not Amazon: Amazon charges every time a file is downloaded. With studios streaming class videos that becomes the single biggest line on the bill. R2 charges nothing to download, which is the entire reason it was chosen.
  • What it needs from you: a free Cloudflare account, then a bucket and one set of keys. Fifteen minutes, and it closes the DNS question and the backup question in the same sitting.

"Do I really have to do the EIN?"

For texting from an ordinary phone number, yes. There is no route to it that skips a registered business, and every provider submits to the same registry. But it is worth being clear about how small the ask is: free, about ten minutes, online, and it does not require an LLC, a sole proprietor gets one with a Social Security number.

What it is not blocking: everything else. The demo runs, the booking works, payments work, email works. Texting is the one feature behind it, and toll-free numbers are the escape hatch if the timing gets tight.

Texting, explained properly

This is the thing that has bitten you before, so here is the whole picture rather than a checklist. The short version: the reason the applications keep failing is that you do not have an EIN, and an EIN is free, takes about ten minutes, and does not require an LLC.

What is actually being asked of you

Since 2021 every business that sends texts from an ordinary ten-digit US number has to register two things with the carriers before a single message goes out: the brand (who is sending) and the campaign (what the messages are and how people agreed to get them). Both go to a single industry registry that every carrier reads. Skip it and messages get silently filtered or blocked, which is the worst possible failure because nothing errors, the texts just quietly stop arriving.

There is no way around the registry. Twilio, Telnyx, Bandwidth, Plivo and Sinch all submit to the same place. Any service claiming to make it disappear is doing one of two things: using toll-free numbers instead, which is a legitimate different route covered below, or sending your messages under their own registered brand, which means the messages are legally theirs, a complaint lands on their account, and you have no standing when they cut you off.

The one fact that unblocks everything

An EIN does not require an LLC, a corporation, or the trust. A sole proprietor can get one online at irs.gov, free, using your SSN, and it is issued immediately at the end of the session. The service is open Monday to Friday, roughly 7am to 10pm Eastern. You do not need to have registered a business anywhere first.

The catch: a brand-new EIN can fail third-party verification because it has not propagated to the business databases the registry checks against, which takes a few weeks. That is the argument for getting one today even though the trust entity is coming , the clock starts now, and it costs nothing.

Your four routes, compared honestly

Route What it is What it needs from you Verdict
A
Sole proprietor
A special registration category built for businesses with no EIN. Verified by a code texted to your own mobile. Your name, mobile, email, address. No EIN. Fine for NetRyse's own texting. Useless here, one campaign, low daily volume, and it cannot be used to send on behalf of other businesses, which is exactly what a twenty studio platform is.
B
Standard brand
recommended
NetRyse registers as the platform, then each studio is registered as its own brand under its own EIN, submitted through the API so a studio owner never sees any of it. An EIN for NetRyse, and each studio's legal name, EIN and address at sign-up. That capture is already built into onboarding. The real answer and the only one that scales. Each studio's reputation is their own, so one studio's mistake cannot take down the other nineteen.
C
Studio brings their own
Every licensee opens their own account, registers themselves, and gives us API keys. Nothing from you. Zero blocker for us and a terrible product. Twenty studio owners will not complete a carrier registration, and the ones who try will call you when it fails.
D
Toll-free verified
A different rail. An 833 or 888 number, verified by the carrier directly rather than through the brand registry. Business name, address, website, use case, expected volume, and the opt-in evidence. Not the same EIN vetting. The fallback, and worth starting in parallel. Roughly one to three weeks. Works fine for reminders and confirmations. Reads a little less local on a member's phone.

Whose name should it be registered in

Your existing NetRyse Twilio account: use it for testing only

  • A suspension is account-wide. If NetRyse's own outreach ever trips something, twenty studios stop texting on the same day.
  • Mixing your own marketing traffic with client traffic muddies the compliance story, and the registry cares about exactly that.
  • The platform account should be owned by the entity that signs the licensee agreements, not by a personal account.
  • The shape to aim for: one platform account, each studio a sub-account inside it with its own number and its own brand.

What to do, in order

  1. Get an EIN today, as a sole proprietor
    Ten minutes on irs.gov, free, issued at the end of the session. Save the confirmation letter as a PDF, every later form asks for the legal name exactly as it appears on it, character for character.
  2. Keep pushing the trust entity in parallel
    Once it exists it becomes the registrant, and it also unblocks Stripe, the insurance named insured and the signature page. The EIN above is a bridge, not a replacement.
  3. Open the platform account and fill in the business profile
    Separate from your existing NetRyse account. You will need:
    • Legal name exactly as printed on the EIN letter, no trading name
    • The EIN itself
    • Entity type, and a street address, never a PO box
    • A live website that describes the business, netryse.com is fine
    • An authorised representative with a business title and a direct phone
    • A support email and phone that a person actually answers
  4. Register the brand
    A few dollars, one time. Usually approved the same day. If it fails, it is almost always the legal name not matching the EIN letter exactly.
  5. Register the campaign, this is the part that gets rejected
    It needs, and reviewers actually read these:
    • A plain description of what the texts are for
    • Two real sample messages, written the way they will actually send, including the business name and the opt-out line
    • Proof of how consent is collected, a live URL or a screenshot of the real form, showing the unticked checkbox and its exact wording. The platform's own lead forms already produce this
    • STOP to opt out and HELP for help, in the footer of the message
  6. Start a toll-free verification at the same time
    Costs nothing to have both in flight. If the campaign gets stuck in a rejection loop, this is what keeps August 12 intact.
  7. Buy one number, send one real text, watch it land in the Inbox
    End to end, with the reply threading back to the right client. Nothing counts as done until this happens once.

The rules that actually produce fines, not the ones that produce warnings

Registration is the carriers' rule. This next part is the law, and it is the expensive one: $500 per message, $1,500 if a court decides it was willful. A single thousand-contact blast with no consent record is a six figure problem.

  • Consent before the first message. An unticked box the person actively ticks, naming the business and the fact that it is texts. Never pre-ticked, never a condition of getting a quote.
  • Keep the receipt. Timestamp, IP, the exact wording shown, and the number. In a claim the business has to prove consent; without the record there is no defence. built
  • STOP kills everything. Not the one automation that sent the message. Every future send to that number, permanently, across every workflow. built
  • Quiet hours. Nothing marketing before 8am or after 9pm in the recipient's own timezone, not yours. built
  • Consent is not blanket. Agreeing to appointment reminders is not agreeing to promotions. The platform keeps those separate, and the member screen shows offers switched off by default.
  • Never import and message a bought or scraped list. The clients importer already refuses to grant SMS consent on import for exactly this reason.

1 · Your list

GetEYT only. The Chat EYT items, the passwords, her insurance, the cohort-expiry deploy, sit on a separate list and are not mixed in here.

Blocking, in this order

Task What it unblocks
1 Pull an EIN today, as a sole proprietor today Texting, and it starts the verification clock that takes weeks
2 The NetRyse entity out of the trust, then its own EIN chasing The registrant of record, Stripe, the insurance named insured, and the signature page. Everything downstream of the contract
3 Two DNS records, so the platform has a web address done Added for you. Both sites are live on https with real certificates
4 Stripe test keys, a new "EYT Platform" account, test mode, never activated now Nothing can run a payment end to end until these exist
4b A free Cloudflare account, then a bucket and one set of keys 15 min Closes two things at once: the backup stops living on a server we own, and student video uploads get somewhere to go
5 Start the texting registration once the EIN is in hand then Class reminders, waitlist texts, lead follow-up. Most of what makes the platform feel alive on the demo

Worth doing, not blocking

Task Why it matters
6 Confirm with AccuWeb that MO.6 to MO.7 is in place, not a rebuild If it is a rebuild, size up now rather than during a busy month
7 Talk to your dad about billing through his company versus a 1099 Jessica asked and it is still open. It also has to match whoever signs
8 Insureon quotes, tech E&O plus cyber, $1M each The retroactive date has to be no later than March 2026 or the platform you already built is uncovered
9 Answer the six questions on the walkthrough with Jessica Two of them, attendance and commission, are blocking real code. The rest shape round one
10 Get geteyt.com pointed at us She owns the domain. Needed before anybody clicks a real link
11 The software company papers, 47.5 / 47.5 / 5 Still unpapered, and a bigger exposure than the Chat EYT contract

2 · My list, before the server

Everything here can be built with no box, no keys and nothing from anyone else. It is ordered so that the last thing finished is the last thing needed.

Read this before the call: the wireframe is ahead of the code

I audited the actual repository rather than trusting the old notes. The platform is genuinely close to finished for the scope it was built to , booking, clients and leads, memberships, payments, payroll, training, the inbox, marketing automations, the HQ console, the front desk kiosk, reports, reviews, referrals and onboarding are all real, working code.

But seven of the eleven things off her wishlist exist as design only. The video library, website hosting, newsletters, the blog, message boards, the retail catalogue and the at-home product library are on the wireframe and are not in the codebase. They were never in the original build scope, they arrived on her sheet last week.

That is not a problem as long as nobody says the word "finished" about them on a call. It is a problem if twenty licensees are shown a screen on August 12 that does not exist yet. So: the three agents already running plus the second wave below close most of the gap, and the honest line to Jessica is that these are designed, specified and being built, not that they are done.

Running right now

Branch What it builds Why it is first
feat/usage-metering Per studio metering of AI and texting, soft caps, alerts at 80% and 100%, an HQ page sorted by worst offender A licensee will ask what happens if they use it a lot, and you need to see the answer before it costs you
feat/pricing-calculator Her starred tool. Real arithmetic off the studio's own prices, pay rates and attendance. Break-even, margin, saved scenarios The thing she called "standardising the industry"
feat/quizzes-coursework Quizzes graded on submission, video practicals uploaded from a phone, an instructor review queue, certificates that stay locked The cohort runs before September regardless of the deadline

Each is in its own worktree with a pre-assigned database migration number so they cannot collide when they merge. Each has to pass type checking, linting, the test suite and the tenant-isolation gate before I look at it.

The second wave, closing the wishlist gap

What Detail
Per studio branding, then newsletters and the blog Capture each studio's colours and logo at sign-up, then recolour the template library to them automatically. Newsletter and blog composing on top. This one goes first because everything visual downstream depends on the branding tokens existing
The video library, both sides Studio-side hosting and course sales, member-side at-home classes, recorded workshops, the podcast, and series a member can buy outright
Message boards and the retail catalogue Licensee and host boards at network level and inside each studio, plus quarterly catalogue ordering from HQ down to the studios
Studio websites Held deliberately until she answers the branding question, because the answer changes the whole shape of it

Then, still with no server

3 · The server, in order

Written as a runbook rather than a to-do list. When the login lands there is nothing to work out, only to run, top to bottom. Nothing here can start early.

Steps 1 to 10 are already done, on both boxes

Hardening, firewall, automatic updates, restart-tested. Docker, the database, the app and the background worker all running. Migrations applied, 98 tables. Demo network loaded, 8 studios and 2,371 bookings. Backups running nightly off-box and a restore actually performed and row-matched. Left in this section: the web address and the certificate, the outside services once their keys exist, and the rehearsal.

Hour one, lock the box before anything is installed on it

  1. Non-root deploy user, key only, passwords off
    Create the user, install the key, then disable password authentication and root login entirely. Do this before the box has been reachable long enough to be found, because it will be found within minutes.
  2. Firewall default-deny, then open exactly three things
    SSH, 80 and 443. Postgres is never open to the internet, not even "temporarily to test something". Add fail2ban on the SSH jail.
  3. Unattended security upgrades
    So the box patches itself without anyone remembering to. This is also a question on the cyber insurance application, and answering it yes is worth real money.
  4. Tailscale, then close SSH to the public internet
    Admin access stops touching the open internet at all. The staging box joins the same network.

Hour two, get it running

  1. Docker and compose, clone, environment variables, first boot
    Secrets go in as environment variables, never into the repository. Bring the web app and the background worker up together, the worker is what makes a lead text feel instant, and a stack without it looks fine and quietly does nothing.
  2. Caddy, TLS and the content security policy
    Certificates issue automatically. Verify the policy actually blocks what it claims to, rather than assuming the header is enough.
  3. Cloudflare in front, origin address never public
    Then confirm the box refuses traffic that has not come through Cloudflare, otherwise the protection is decorative.
  4. Backups every night to object storage, off the box
    Then restore one into the staging box and open it. A backup nobody has restored is not a backup, it is a hope. This step is not optional and it is not deferred.
  5. The staging box, same build
    So a database migration is never first tried on the machine that holds twenty studios' member records.
  6. Health checks and alerting
    Something that shouts on Telegram when the site, the worker or the nightly backup fails. Test it by breaking something on purpose.

Then, connecting the outside world

  1. Stripe end to end, in test mode
    Charge, refund, a dispute, and a webhook delivered twice on purpose to prove it does not double-charge anybody.
  2. Texting, per studio
    A sub-account per studio provisioned through the API. Send one real message, reply to it from a real phone, watch it thread into the right client's inbox. Then test STOP and confirm it silences every automation and not just the one that sent it.
  3. Email sending from each studio's own domain
    The sending records per studio, so a studio's newsletter arrives from them rather than from us. Verify one lands in a real inbox and not in spam.
  4. Seed the eight demo studios and walk the whole demo twice
    On the real box, at the real speed, with the network as it will be on the day.
  5. A link for Jessica and two trusted licensees
    Early August, quietly. The point is to be told the obvious thing that nobody who built it can still see.

The automations, grouped

What already runs on its own, sorted by what sets it off. This is the real catalogue from the codebase, not a wish list, fifteen automations and thirty-two message templates are written and working, waiting on a phone number and a payment key to leave the building.

A new lead arrives

Set off by What happens Goes out as Why it exists
A lead form is submitted Instant welcome Text and email Speed of first reply is the single biggest factor in whether a lead books
The same lead, still cold Follow-up on day 1, day 3 and day 7 Text, email, text Stops on a reply or a booking, so nobody gets chased after they have already said yes

Classes and bookings

Set off by What happens Goes out as Why it exists
A class is booked Booking confirmation Email Transactional, so it goes even to someone who has opted out of marketing
24 hours before Reminder Text The single highest return automation a studio runs
2 hours before Second reminder Text Catches the late cancel while the spot can still be resold
A spot opens on a full class Waitlist promotion Text Runs on its own in the background, so a spot is never wasted overnight
Somebody does not turn up No-show follow-up Text The moment a member is most likely to quietly drift away

A member's life at the studio

Set off by What happens Goes out as Why it exists
First ever visit Welcome Email The window where a first-timer decides whether to come back
A visit completes Review request Text Asked while it is fresh, which is the only time people actually write one
30 days with no visit Win-back Email Cheaper to bring one back than to find a new one
A birthday Birthday message Text Small, and members remember it
A visit milestone Milestone note Text The 50th and 100th class are worth marking

Money

Set off by What happens Goes out as Why it exists
A card fails Payment failed notice, then a retry, then a final notice Email Recovers most failures without the owner ever knowing there was one
A tuition instalment falls due Charge the plan Charge, then a receipt Teacher training is paid over months, and chasing it by hand is where studios lose money
A gift card is bought Deliver it Email Straight to the recipient, on the date chosen
Stripe reports anything Account, checkout, invoice, refund and dispute sync Nothing visible Keeps the studio's numbers true without anybody reconciling by hand

Teacher training

Set off by What happens Goes out as Why it exists
An application comes in Application received Email So a prospective student is not left wondering
They enrol Registration confirmation Email Dates, requirements and what they owe, in one place
Homework becomes due Materialise and send the assignment Email The cohort moves together instead of the instructor chasing
Every requirement is met Certificate issued Email with the certificate And never a moment before, which is the whole point of the gate
A required document is unread Acknowledgement reminder Email How HQ proves a standard was actually received, not just published

Underneath, where nobody sees it