Verify Agave Studio
Verify a message from Agave Studio
Scammers are impersonating Squarespace designers and emailing their clients. This page is the official record of how Agave Studio communicates, how we invoice, and how to confirm that a message actually came from us.
Bookmark this page. If a message claims to be from Agave Studio and it does not match what is on this page, it is not from us.
This page is the authority. It overrides any email, text message, invoice, or contact form reply you receive, no matter how convincing it looks.
How we actually communicate
Our only domain is agave.studio. Every legitimate email from us comes from an address ending in @agave.studio.
Our only email addresses:
Our client portal: portal.agave.studio. Our phone: (970) 205-9286.
We never contact clients from Gmail, Outlook, or any free email service. If you see agave.studio inside a Gmail address, or a lookalike domain with an added letter, missing letter, hyphen, or .com on the end, it is fake.
What Agave Studio will never do
These are permanent commitments, not guidelines.
We will never send you an urgent payment request.
We will never send an invoice you have not already discussed with Clinton by phone, video, or in an active email thread.
We will never introduce a new payment platform. Our invoicing runs through HoneyBook and nowhere else.
We will never ask you to pay by wire transfer, Zelle, Venmo, PayPal friends and family, gift card, cryptocurrency, Fiverr, or Upwork.
We will never ask you to reply "YES" to authorize work.
We will never ask for your password, login credentials, or a two-factor authentication code.
We will never contact you about a compliance audit, a compliance license, an SSL renewal, an accessibility mandate, or a platform-wide security review. None of these things exist.
We will never contact you out of the blue with a payment deadline. The only payment reminders you receive from us concern an invoice already in your hands, under a contract you have already signed. See the section below.
We will never send mass, impersonal emails about a problem with your site. If something is genuinely wrong, Clinton contacts you individually and by name.
How real work actually gets authorized
Every paid engagement with Agave Studio follows this documented sequence. There are no exceptions and no shortcuts.
A conversation happens first. A scheduled call, or a reply inside an email thread that already exists between us.
Scope is put in writing. You receive a written description of the work before anything is billed.
A proposal and contract arrive through HoneyBook, from an agave.studio address.
A 50% deposit invoice is issued through HoneyBook once the contract is signed.
The remaining balance is invoiced before launch.
Launch includes a live Zoom training session with Clinton.
If a request skips any of these steps, it did not come from us.
The one exception: a past due invoice
There is exactly one situation in which you would hear from us about payment and your site's availability in the same message, and that is an invoice that has gone past due under a signed contract. We would rather be straightforward about that than publish a list with a hole in it.
A real notice of that kind looks nothing like the scam:
It refers to a specific invoice you already received through HoneyBook, by number and by date.
It refers to the contract you signed, and to the clause it relies on.
It follows earlier reminders and, in almost every case, a direct conversation. It is never the first you hear of it.
It comes from clinton@agave.studio, usually inside an email thread that already exists between us.
It asks you to pay the original HoneyBook invoice. It never introduces a new payment method, a new platform, or a new account to send money to.
It never mentions compliance, licensing, security reviews, accessibility mandates, or Squarespace policy.
A scam message invents an outside threat: Squarespace, a regulator, a compliance body, a law you have never heard of. A real notice from us concerns our agreement and nothing else. Either way, a phone call to (970) 205-9286 settles it in under a minute.
Confirming a suspicious message
If anything feels off, stop and verify. Do not reply to the message itself. A reply, even a single word, tells a scammer that your address is active and gives them an opening.
Confirm through one of these channels instead:
Call (970) 205-9286. This is the fastest option and the one we recommend.
Reply inside an email thread you already have with us, one you can confirm predates the suspicious message.
Use the contact form at agave.studio/contact.
Message us through the client portal at portal.agave.studio.
We would rather look at ten false alarms than have one client lose money. There is no such thing as bothering us with this.
Requests involving access to your site
Any request to add an administrator, invite a contributor, transfer a domain, change DNS records, or update billing information will be confirmed with you by phone or video before it happens. Live voice confirmation, every time, in both directions.
This applies even when the request appears to come from Clinton. If you receive one and we have not spoken about it live, treat it as fraudulent.
Known scam patterns
Scammers scrape designer portfolios, "Built by" footer credits, case studies, and public directories to work out which clients belong to which designer. Then they email those clients, using the designer's real name, logo, and sometimes their headshot.
Patterns confirmed so far:
Claims that a "compliance license" needs configuring or renewing
Claims that a "compliance audit" is required for GDPR, CCPA, or accessibility standards
Claims that a "security review" or SSL certificate fix is needed
Threats that your domain will be restricted, suspended, or taken offline
Claims that a Squarespace "platform update" will cause downtime on your site
References to invented Acts or laws to manufacture legal pressure
Requests to simply reply "YES" to approve work
Invoices routed through Fiverr, Upwork, or a similar third party
Messages arriving through your website contact form rather than by email
Accusations that your website is infringing or "committing theft"
Greetings such as "Hi Dear," or wording lifted from your real past emails with us
Gmail addresses built to contain our business name
Lookalike domains with an extra character, a missing character, or an added .com
The tactics change constantly. This list is updated as new versions surface.
About the platform itself
Squarespace has confirmed that there has been no security breach. Your account has not been compromised, and neither has ours. These messages are built from information that is publicly visible on the internet, not from stolen data.
Receiving one of these emails does not mean anything is wrong with your website. Your site stays safe unless you hand over credentials or grant access to the impersonator.
If you received a fraudulent message
Do not reply, click any link, open any attachment, or agree to anything.
Do not share login information or grant site access until you have confirmed the request with us through one of the channels above.
Forward the full message, including headers, to reportphishing@squarespace-security.com.
Report it inside your email client as phishing or spam.
Forward it to us at clinton@agave.studio so we can track the pattern and warn other clients.
If you have already sent money or shared sensitive information, file a report at ic3.gov and contact your bank or card issuer immediately.
If you have already paid a scammer, tell us anyway. There is nothing to be embarrassed about here. These messages are convincing by design, and knowing about it helps us protect everyone else.
Update log
9/1/2026 Verification page published.
Agave Studio LLC, registered in Golden, Colorado, serving Denver and nationwide. Squarespace Circle member and Platinum Partner.