What Lolly does that today's creative tools do not, and what it deliberately leaves to them.
For the tool-by-tool version, one page each for Canva, Adobe, Figma, rendering APIs and online converters, see Lolly compared, tool by tool. Each page states what the other tool does better and what Lolly does instead.
Pilot status: Lolly is a closed-pilot prototype, not a finished product, and its security is currently undergoing SUSE's strict infrastructure hardening, preparing for enterprise scale. The Adoption & Governance page covers the current state.
Today's tools
Each ring below scores how completely a product class delivers a capability as shipped today - not as marketed - with every class scored on its best representative. Lolly is scored with the same knife: it takes the only red ring on the board, for maturity. Open a row name for the reasoning behind its scores. Columns are sorted by the Overall completeness row at the top - the mean of the scored rows, with the spend row excluded.
| Capability | Lollyconstraint-first | Penpotopen design | CanvaAffinity Cavalry |
Adobedesktop pro | Brand DAMFrontify Bynder |
Cloudinarymedia pipeline | Figmaonline pro | Render APIsBannerbear Placid Creatomate |
|---|---|---|---|---|---|---|---|---|
| Overall completenessunweighted mean - weight rows for your own context · columns are sorted by this row | 84 | 70 | 57 | 48 | 41 | 41 | 41 | 34 |
Production maturity & track recordCanva, Adobe, Figma, Bynder/Frontify: a decade-plus at massive scale. Render APIs: years in production pipelines. Penpot: shipping, large community, younger at enterprise scale. Lolly: closed pilot, security hardening underway, no public case studies. Cloudinary: 2012, enterprise media infrastructure at global scale. |
25 | 75 | 100 | 100 | 100 | 100 | 100 | 75 |
Mass generation from data (CSV / API)Lolly: batch grid + CLI, one file per row. Canva: Bulk Create + Autofill API - real, but Enterprise-gated, async, text/image fields only; Affinity Publisher adds desktop data merge. Adobe: InDesign data merge and scripting. Figma: Buzz fills templates from CSV or XLSX, free in beta (Aug 2026) - cloud- and account-gated, 50. Penpot: open API/MCP, not purpose-built. Render APIs: this is their entire product - account- and cloud-gated, so 75 under the method rule. DAM: Studio-style batch create and resize. Cloudinary: URL-driven overlays and named transforms derive variants at scale - account-gated, 75. |
100 | 50 | 50 | 50 | 75 | 75 | 50 | 75 |
Offline & air-gap operationLolly: static deploy, no server in the render path, MDM/air-gap. The Canva column is scored on its best family member: Affinity (free since Oct 2025) runs offline as a desktop suite once a verified account activates it - 75, the same deduction Adobe takes. Canva's own Offline (2026) still edits pre-synced designs only, per device, in a 14-day window. Adobe: desktop apps run offline; licensing phones home. Figma: cached-file viewing and limited editing. Penpot: self-host on your infra behind a firewall (server required). Cloud APIs and DAM: none. |
100 | 75 | 75 | 75 | 0 | 0 | 25 | 0 |
On-device rendering - data never leavesLolly: renders and converts in-browser or CLI, locally; zero upload. Adobe: local desktop rendering, but cloud services and telemetry in the suite. Figma: canvas renders locally, files live in Figma's cloud. Penpot: 90 - rendering happens in the browser and the save target is a server that can be your own sovereign private cloud, even your own laptop, with private export throughout; only the server hop separates it from Lolly. Canva itself is server-side by design; the column's 75 is Affinity - local desktop rendering, account activation and telemetry, the same shape as Adobe. Render APIs, DAM: server-side by design. |
100 | 90 | 75 | 75 | 0 | 0 | 25 | 0 |
Hard brand constraints (structural)Lolly: rules compiled into template code - off-brand output is impossible, not just discouraged. Canva: element locks - permission-based, admin-set and static: no template logic such as conditional logo switching or responsive recomposition at fill time, and Canva AI does not yet respect Brand Controls - 50. Render APIs: templates are fixed (only declared fields vary) but no governance layer. DAM: locked templates with restrictions. Figma: Buzz templates hold locked guidelines at fill time; the design surface stays review-enforced - 50. Penpot: tokens and systems enforced by review, not runtime. Adobe: libraries, little enforcement. Cloudinary: presets and Enterprise-gated transformation templates fix operations, not brand layout - 50. |
100 | 50 | 50 | 25 | 75 | 50 | 50 | 75 |
C2PA provenance, signed at creationAdobe: the broadest shipped implementation (Photoshop, Lightroom, Premiere, Firefly) - signing happens locally in the desktop apps and in the cloud for the Content Authenticity web app, and nothing signs without an Adobe account and an Adobe-provisioned identity, so it is account-gated end to end: 75 under the method rule. Lolly: on-device key generation, offline signing, plus pixel imprint - no account anywhere; the on-device key reads as unverified in stock validators (the interim trust list froze Jan 2026) until an identity or an organization's own CA vouches for it, and the stack is pilot-stage and unaudited, so 75. Penpot: 50 via the official Lolly Export plugin - the same on-device engine signing Lolly uses, opt-in rather than default (and disclosed plainly: it is Lolly's own plugin). No evidence of C2PA writing in Canva, Figma, render APIs or DAM as of Aug 2026. Cloudinary: 50 - signs images on delivery (fl_c2pa, CAI member since 2020), attesting delivery by Cloudinary rather than creation by you. |
75 | 50 | 0 | 75 | 0 | 50 | 0 | 0 |
CLI, pipeline & AI-agent automationLolly: CLI, TUI, MCP server, URL mode - one engine everywhere. Render APIs: API-first, webhooks, integrations - account- and cloud-gated, so 75 under the method rule. Penpot: open API, plugins, official MCP server. Canva: Connect API - Enterprise-gated, async, rate-limited. Adobe: UXP/ExtendScript plus Firefly APIs. Figma: strong REST/plugin API, no render pipeline. DAM: asset-management APIs. Cloudinary: API-first media pipeline - account-gated, 75. |
100 | 75 | 50 | 50 | 50 | 75 | 50 | 75 |
Live collaboration (real-time co-editing)The capability that trades most directly against offline. Figma: the scale benchmark - 200 simultaneous editors, up to 500 people in a file - account and cloud required. Canva: mature real-time editing across the product, same precondition. Penpot: real-time multiplayer with live cursors; self-hosting lifts the vendor-account precondition, but a server is still required. Lolly: pairwise P2P shipped - an invite/accept ceremony (QR, link or code), LAN-first, zero server, no account, works fully air-gapped - no large rooms, so Partial; the only column that collaborates with no internet at all. Adobe: Live Co-Editing in beta, cloud documents only. Render APIs: no editing surface. DAM: comments and approvals, not canvas co-editing. Cloudinary: DAM comments and workflows, no canvas co-editing. |
50 | 75 | 75 | 25 | 25 | 25 | 75 | 0 |
No design skill requiredCanva: the category benchmark for ease. DAM: fill a locked template. Lolly: fill in fields - but someone technical must author tools first (the cold-start cost sits with builders, not producers). Render APIs: swaps design skill for developer skill. Adobe, Figma, Penpot: professional tools. Cloudinary: the media library is easy; transformations are developer territory. |
100 | 25 | 100 | 25 | 100 | 50 | 25 | 50 |
Open source, self-hosted, no lock-inPenpot: MPL-licensed, 51k+ stars, self-host via Docker/K8s - fully verifiable today. Lolly: MPL-2.0, the repository is public (github.com/lolly-tools/lolly), OBS builds, no contributor agreement - and it is young: months in public, no external audit, a community still forming, with SUSE maintaining it as a user of its own systems. 75 while youth is the honest deduction. Everything else is proprietary SaaS or proprietary desktop. |
75 | 100 | 0 | 0 | 0 | 0 | 0 | 0 |
Cost at production scaleLolly and Penpot: zero marginal cost on your own hardware. Render APIs: metered - roughly $0.005–0.049 per image, credits often expiring monthly. Canva/Figma: per-seat; Canva's automation needs Enterprise, though Affinity itself is free since Oct 2025. Adobe: premium per-seat suite. DAM: sales-led enterprise quotes, MAU or seat models. Cloudinary: credit-metered across transforms, storage and bandwidth - 25. |
100 | 100 | 50 | 25 | 25 | 25 | 50 | 25 |
Annual medium enterprise spendIndicative list-price arithmetic for a medium enterprise - think 500-5000 people - August 2026: a guess range, not a quote; deals vary and the seat mix dominates. Ring = how much of the board's largest annual spend (US$500k) you keep; the number in the ring is each range's upper bound. Canva (US$75k-400k; Affinity free since Oct 2025 pulls the design-seat share down), Adobe (US$100k-500k) and Figma (US$30k-250k) assume the realistic creative-seat share of an organisation this size - tens to hundreds of seats, not a licence for every employee. Render APIs price by usage (US$5k-60k). DAM is quote-only, commonly US$50k-250k and up. Penpot is hand-set at 99: "your server" can be your own laptop - a small technical hurdle at well under 1% of an Adobe-scale spend. Lolly: US$0 by licence - the apps ship free, run offline and keep working in perpetuity; works on devices immediately, config optional; hosting an instance is an organisation's choice, not a cost of entry. Cloudinary: US$30k-150k, credit-based; enterprise contracts commonly sit near US$82k. |
$0 | $0 | $400k | $500k | $250k+ | $150k | $250k | $60k |
Capability completeness across today's creative tools, researched August 2026. Scoring: 0 absent, 25 workaround-grade, 50 real but gated or partial, 75 strong with caveats, 100 core competency.
signed by Lollypositioning-comparison.htmlHTMLAI generatedgenerated by ClaudeCheck it yourselfGet the signed filepixels, not shapes38 KBScoring notes. Lolly's scores assume its published claims hold, which is why maturity is its one red ring: closed pilot, security hardening in progress, nothing audited yet. Research moved several cells.
Canva is scored on its best family member per row, since it owns Affinity and Cavalry (both given away October 2025). Offline and on-device rendering score 75 through Affinity - a desktop suite that still needs a verified account and carries telemetry, the deduction Adobe also takes - while Canva's own offline mode edits only pre-synced designs, one device, limited window. Autofill scores 50: real but Enterprise-gated, async, text and image only. Figma's mass generation rose 25 to 50 when Buzz shipped spreadsheet fill (free beta, August 2026).
One rule governs the board: Full (100), on rows that touch your content or identity, needs a capability you can use with no account and no cloud precondition; rows describing the product itself (maturity, ease of use) are exempt. It costs Adobe on provenance: the broadest shipped C2PA (Photoshop, Lightroom, Premiere, Firefly) signs locally and in the cloud, but never without an Adobe account and identity, so 75. It caps the render APIs on mass generation and automation for the same reason.
Lolly's provenance 75 reflects on-device offline signing: architecturally stronger but unaudited, and a device key reads as unverified in stock validators until an identity or an organization's own CA vouches for it. Penpot's 50 arrives through the official Lolly Export plugin: the same engine signing, opt-in, disclosed as Lolly's own. Penpot also takes the board's only off-scale ring, 90 on on-device rendering - browser canvas, save to your own sovereign cloud (even a laptop), private export; only the server hop separates it from Lolly. Cloudinary gets its own column: a media pipeline (DAM, transform API, CDN), and the only cloud column shipping C2PA (50, because fl_c2pa signs on delivery, attesting delivered-by-Cloudinary, not made-by-you).
Live collaboration runs the other way: Figma sets the scale benchmark (200 editors) and Lolly's pairwise, air-gapped P2P scores Partial. Price is a guess, labelled as such: list-price arithmetic on realistic seat mixes, wide on purpose, for scale not procurement. Render APIs take 75 on constraints: templates locked, no brand-governance layer.
The gap: nothing shipping today is constraints-first and offline with no account and no server in the render path, and no one has copied the account clause. Lolly now ships its own open canvas - Design, a direct-manipulation free canvas - but colours, type and assets on it conform to the brand globals, so even free arrangement stays constraints-first.
What Lolly still is not is an unconstrained design suite; designers will continue to use Illustrator and Figma for bespoke work - and when that work needs to become a governed, reproducible asset, the Design tool's Import a design brings the finished Figma, Penpot, Illustrator, InDesign or PDF file onto the canvas as editable, brand-conformed boxes.
signed by Lollyvector SVGCheck it yourselfGet the signed file13 paths444 nodes33 groups14 KB
signed by Lollyvector SVGCheck it yourselfGet the signed file13 paths431 nodes33 groups14 KB
Use it for
- Rapid generation of operationalised creative assets (event tiles, badges, signatures, alerts)
- Free-form arrangement on the open canvas (Design) when the pieces - colours, type, icons, images - must stay conformed to the brand globals
- Landing a finished Figma, Penpot, Illustrator, InDesign or PDF design (the Design tool's Import a design) so it can be edited, governed and re-rendered deterministically in every Lolly format
- One-to-many "fill in three fields, get the finished asset" flows - including bulk runs from a spreadsheet/CSV in the
/probatch grid (paste or import rows, one finished asset per row, download as a zip) - Always-on, recurring branded outputs
- Things where central control of brand expression matters more than expressive flexibility
Deck Studio is a good measure of the ceiling here: a whole slide deck declared as data, laid out live on the canvas and exported as a native editable PowerPoint.
signed by Lollyvector SVGCheck it yourselfGet the signed file163 paths~17k nodes265 groups2 images250 KB
signed by Lollyvector SVGCheck it yourselfGet the signed file163 paths~17k nodes265 groups2 images250 KB
Do not use it for
- Bespoke or flagship hero content (billboards, major videos)
- Unique campaign work that genuinely needs a designer
- Ideation that needs to escape the brand system entirely - Lolly's open canvas still conforms colours, type and assets to the brand globals, and that's the point
Innovate probabilistically, scale deterministically
Most "AI creative" pitches put the model on the wrong side of an old line. Scribes and illuminators already settled where it falls: you work loose on the sketch, where anything can be tried and nothing is committed, and then you go to the printing press, which is intimidating exactly because it commits. The sketches were where the art was. The press was how it travelled. Two instruments, two jobs, each inventive in its own way, and the printed work could be trusted because the press kept its promise on every pull.
Lolly is the press, not the sketch. Bring whatever you like to the ideation - a model, a designer, a napkin - but the moment an idea has to become ten thousand assets it goes through something that renders the same way every time, from inputs anyone can read back. That is what the comparison above is really about: not who has the better generator, but who makes the committed step reproducible.
Trust the creative process, scale with rigour.
Approve the tool, not the file
Every other tool on the board produces a file that then has to be checked - a brand manager in a Slack thread, legal on the disclaimer, a round of changes, another review. Lolly moves the approval one step upstream. The brand rules - exact hex codes, licensed font files, bleed margins, spacing - are hard-coded into the tool's HTML and CSS, so the template cannot emit an off-brand asset. The layout itself does the enforcing.
So you stop approving outputs and start approving the tool that makes them. Approve it once, and every asset it ever produces is pre-approved by construction - no human in the loop, no review cycle, at any volume.
This is the change the deterministic engine actually delivers: it isn't a faster version of the old approval process, it removes the process. For the creative team it's a guard-rail, not a replacement - you still throw the ball (the data, the copy, the image) and the code is the bumper lane that keeps every throw out of the gutter.
signed by Lollyvector SVGCheck it yourselfGet the signed file54 paths~3.3k nodes114 groups2 images58 KB
signed by Lollyvector SVGCheck it yourselfGet the signed file54 paths~3.3k nodes114 groups2 images58 KB
| Approving assets the old way | Approving the tool, the Lolly way |
|---|---|
| Every finished file is checked, one at a time | The tool is checked once |
| Request → designer builds → brand review → legal check → changes → re-review | One parameter change → finished asset |
| Designer, brand manager, legal and requester all in the loop | The producer, on their own |
| Days per asset | Seconds per asset |
| 10,000 assets = 10,000 review cycles | 10,000 assets = zero (the template was already approved) |
What this uniquely provides
- Wild design potential delivered safely in context. Tools can express adventurous design ideas inside hard coded guard-rails.
- Software-defined content automation that returns the final asset. Input → final file. No "now save it from your design tool and post-process it."
- Tools compose tools. One tool can embed another tool's render and return it as part of a single finished asset, with no tool-to-tool code coupling - a primitive no open-canvas or DAM-templating product on the board offers.
- Vendor neutrality. Full feature and cost control. Open-source engine. Tools and assets are git-tracked content, not locked in a SaaS database.
The first of those is the one people underestimate. A poster-grade city map, drawn as true vector road and water paths, from a dropdown and two colour fields that cannot be pointed outside the brand:
signed by Lollyvector SVGCheck it yourselfGet the signed file8 paths~25k nodes7 groups287 KB
signed by Lollyvector SVGCheck it yourselfGet the signed file8 paths~25k nodes7 groups287 KB
Content sovereignty
There is a name for what the previous section adds up to: sovereignty. Your media pipeline runs on hardware you own. Your brand - the tokens, the fonts, the logos, the tools that enforce them - lives in files you hold, in version control you control, not in a vendor's database with an export button. Rendering happens on the device in front of you, so an asset never transits a third party to exist, and the whole path from input to finished file is open source and inspectable. If every SaaS design vendor disappeared tomorrow, a Lolly deployment would not notice.
This matters to anyone whose work should outlive a subscription: the parent whose photo book lives on that laptop as much as the public body whose brand library sits under procurement rules. For organisations - public bodies, regulated industries, anyone whose brand is a strategic asset rather than a decoration - "where does our content live and who can turn it off" is a governance question, not a preference. Sovereignty here is a property of the architecture rather than a hosting feature added for compliance, and the Privacy Policy and Verify It Yourself pages exist so you can check that claim rather than take it.
Underneath it all is one promise, stated as a commitment rather than a feature: if it renders on your device, it is free forever. The engine, the shells, the tools, the formats - the entire on-device creative path is open source and stays that way. That promise has a mechanism: a version that has been released is licensed so it cannot be taken back, and no contributor agreement exists that could relicense the work later. The whole boundary fits in one sentence: everything that renders on your device is free and open source, forever; coordinating people and machines across a network is the job of a separate control plane, lolly.work.