Skip to content
No. 01 / Trust & security

What runs the site. What to allowlist. Where your data goes.

The page to forward to your IT team: one apex domain to allowlist, subprocessors documented by function, US data residency, and no model training on your content — ever.

Last updated: 2026-06-22

No. 02 / Controls

Security at every layer.

The controls your security team will ask about, in the order they ask.

Encryption in transit

TLS 1.3 preferred, TLS 1.2 minimum — modern cipher suites only. Every subdomain is HTTPS-only (HSTS).

Encryption at rest

AES-256 on the database and on object storage.

Data residency

United States (US-East). Data at rest and compute are US-only; EU transfers ride the SCCs incorporated into our DPA.

No model training

Never on your briefs or decks — contractually prohibited at every LLM and voice-agent vendor (DPA Annex II).

No. 03 / Data lifecycle

Know what happens to the material you provide.

Deletion is self-serve — /app/settings → Delete account cascades to all owned briefs and decks. What we never do is documented just as plainly.

Soft-deleted immediately; hard-purged from primary storage within 30 days
Encrypted backups retained up to 35 days, then destroyed
No selling, sharing, or renting personal data to advertisers — GPC and DNT honored
No third-party browser trackers on app.askdeck.ai — first-party analytics only
No PHI: we are not a HIPAA Business Associate — do not put PHI in a brief
We never see card data — a PCI-DSS Level 1 processor handles all payment instruments
Deletion timeline
1.Delete account — /app/settingsImmediate
2.Cascade to owned briefs and decksImmediate
3.Hard-purge from primary storage≤ 30 days
4.Encrypted backups destroyed≤ 35 days
No. 04 / For your IT team

One wildcard covers everything.

Allowlist *.askdeck.ai under Business / Productivity / SaaS — all subdomains are HTTPS-only and TLS-only (HSTS).

Wildcard

*.askdeck.ai

One entry covers the marketing site, the app, and the API. Category requested: Business / Productivity / SaaS.

Marketing

askdeck.ai · www.askdeck.ai

The public site — this page included.

App

app.askdeck.ai

The authenticated workspace: deck library, brief form, brand kit.

API

api.askdeck.ai

HTTPS REST, plus live deck-build progress on a long-lived HTTPS response over port 443 — no WebSocket. Proxies that cut idle connections only make the progress view reconnect; generation completes on the server.

Suggested email

If askdeck.ai is blocked on your corporate network, the fastest path is someone on the inside asking IT for an exception — most allowlist requests are resolved within 24 hours when they come from a verified employee.

Hi — I'm trying to access askdeck.ai, an AI-powered tool that drafts editable PowerPoint decks from a short brief. Could you allowlist *.askdeck.aiunder the Business / Productivity / SaaS category? The vendor's full security posture — subprocessors, encryption, data residency, deletion — is published at https://askdeck.ai/trust. If you need a security questionnaire, DPA, or vendor risk profile, the vendor responds at [email protected] within 3 business days.

No. 05 / Subprocessors

Every third party that touches your data, by function.

The categories are set out in Annex III of our DPA; request the current named list for your security team. We give 30 days' written notice before adding or replacing a subprocessor (DPA §6).

Subprocessors — categories per DPA Annex III
FunctionProvider (by category)Data received
Hosting (compute)Cloud compute provider — United StatesService traffic + ephemeral runtime state
DatabaseManaged relational database — United States, encrypted at restAccounts, briefs, decks, billing records
Object storageObject storage — United States, encrypted at rest.pptx files, audio recordings, brand-kit assets
Edge / CDN / DNSCDN / edge-security providerTraffic metadata + IP addresses
AuthenticationIdentity provider — passwordless / OAuthEmail + authentication identifiers (no passwords stored by us)
PaymentsPCI-DSS Level 1 payment processorBilling details + card data (the processor receives it; we do not)
LLMEnterprise LLM providerBrief text; contractually no model training on customer data
VoiceTelephony provider — inbound calls + voice agentPhone numbers, call audio
SMS / iMessage / RCSMessaging providerPhone numbers, message content, delivery receipts
Voice agent runtimeSpeech-to-text + voice-agent runtime providerCall audio + transcripts
Transactional emailTransactional email provider — outbound + inbound parsingEmail addresses + message contents
Webhook deliveryWebhook delivery providerWebhook payloads sent to customer endpoints
Product analyticsFirst-party product analytics, served from our own domainPage-view + click events; opt-in session replay; GPC honored

All processing is performed in the United States. EU customers: international transfers are governed by the EU SCCs incorporated into our DPA (Module Two).

No. 06 / Web-gateway categorization

Still showing as Uncategorized?

We've requested categorization with the major secure web gateways. Your IT can re-query the database or submit a recategorization request — most vendors honor it within 1–3 business days. Submission receipts on request.

Palo Alto Networks PAN-DB

urlfiltering.paloaltonetworks.com

Symantec / Broadcom WebFilter

sitereview.bluecoat.com

Fortinet FortiGuard

fortiguard.com/webfilter
No. 07 / Contacts

One inbox per topic.

Quick security questions answered the same business day; full questionnaires and vendor reviews within three business days.

Security & vendor review[email protected]
AI deck intake (email)[email protected]
AI deck intake (SMS / iMessage)+1 (332) 239-0932
Security disclosures (RFC 9116)/.well-known/security.txt
No. 08 / Procurement

Enterprise review materials.

Provide procurement and security teams with the documentation they need to evaluate the service.

Data processing agreement

Published at /dpa — EU SCCs (Module Two) incorporated; Annex II prohibits model training on Customer Content.

Named subprocessors

The current named list within each Annex III category, furnished to security teams on request — 30 days' written notice before changes (DPA §6).

Security questionnaires

Questionnaires, DPAs, and vendor risk profiles answered at [email protected] within 3 business days.

security.txt

Security disclosures per RFC 9116, published at /.well-known/security.txt.

Need a deeper security review?

Quick questions answered the same business day; full questionnaires and vendor reviews within three business days.