What runs the site. What to allowlist. Where your data goes.
The page to forward to your IT team: one apex domain to allowlist, subprocessors documented by function, US data residency, and no model training on your content — ever.
Last updated: 2026-06-22
Security at every layer.
The controls your security team will ask about, in the order they ask.
Encryption in transit
TLS 1.3 preferred, TLS 1.2 minimum — modern cipher suites only. Every subdomain is HTTPS-only (HSTS).
Encryption at rest
AES-256 on the database and on object storage.
Data residency
United States (US-East). Data at rest and compute are US-only; EU transfers ride the SCCs incorporated into our DPA.
No model training
Never on your briefs or decks — contractually prohibited at every LLM and voice-agent vendor (DPA Annex II).
Know what happens to the material you provide.
Deletion is self-serve — /app/settings → Delete account cascades to all owned briefs and decks. What we never do is documented just as plainly.
One wildcard covers everything.
Allowlist *.askdeck.ai under Business / Productivity / SaaS — all subdomains are HTTPS-only and TLS-only (HSTS).
*.askdeck.ai
One entry covers the marketing site, the app, and the API. Category requested: Business / Productivity / SaaS.
askdeck.ai · www.askdeck.ai
The public site — this page included.
app.askdeck.ai
The authenticated workspace: deck library, brief form, brand kit.
api.askdeck.ai
HTTPS REST, plus live deck-build progress on a long-lived HTTPS response over port 443 — no WebSocket. Proxies that cut idle connections only make the progress view reconnect; generation completes on the server.
If askdeck.ai is blocked on your corporate network, the fastest path is someone on the inside asking IT for an exception — most allowlist requests are resolved within 24 hours when they come from a verified employee.
Hi — I'm trying to access askdeck.ai, an AI-powered tool that drafts editable PowerPoint decks from a short brief. Could you allowlist *.askdeck.aiunder the Business / Productivity / SaaS category? The vendor's full security posture — subprocessors, encryption, data residency, deletion — is published at https://askdeck.ai/trust. If you need a security questionnaire, DPA, or vendor risk profile, the vendor responds at [email protected] within 3 business days.
Every third party that touches your data, by function.
The categories are set out in Annex III of our DPA; request the current named list for your security team. We give 30 days' written notice before adding or replacing a subprocessor (DPA §6).
| Function | Provider (by category) | Data received |
|---|---|---|
| Hosting (compute) | Cloud compute provider — United States | Service traffic + ephemeral runtime state |
| Database | Managed relational database — United States, encrypted at rest | Accounts, briefs, decks, billing records |
| Object storage | Object storage — United States, encrypted at rest | .pptx files, audio recordings, brand-kit assets |
| Edge / CDN / DNS | CDN / edge-security provider | Traffic metadata + IP addresses |
| Authentication | Identity provider — passwordless / OAuth | Email + authentication identifiers (no passwords stored by us) |
| Payments | PCI-DSS Level 1 payment processor | Billing details + card data (the processor receives it; we do not) |
| LLM | Enterprise LLM provider | Brief text; contractually no model training on customer data |
| Voice | Telephony provider — inbound calls + voice agent | Phone numbers, call audio |
| SMS / iMessage / RCS | Messaging provider | Phone numbers, message content, delivery receipts |
| Voice agent runtime | Speech-to-text + voice-agent runtime provider | Call audio + transcripts |
| Transactional email | Transactional email provider — outbound + inbound parsing | Email addresses + message contents |
| Webhook delivery | Webhook delivery provider | Webhook payloads sent to customer endpoints |
| Product analytics | First-party product analytics, served from our own domain | Page-view + click events; opt-in session replay; GPC honored |
All processing is performed in the United States. EU customers: international transfers are governed by the EU SCCs incorporated into our DPA (Module Two).
Still showing as Uncategorized?
We've requested categorization with the major secure web gateways. Your IT can re-query the database or submit a recategorization request — most vendors honor it within 1–3 business days. Submission receipts on request.
Cisco Talos / Umbrella
talosintelligence.com/reputation_center/supportPalo Alto Networks PAN-DB
urlfiltering.paloaltonetworks.comSymantec / Broadcom WebFilter
sitereview.bluecoat.comZscaler
csi.zscaler.comFortinet FortiGuard
fortiguard.com/webfilterForcepoint
csi.forcepoint.com/SubmitOne inbox per topic.
Quick security questions answered the same business day; full questionnaires and vendor reviews within three business days.
Enterprise review materials.
Provide procurement and security teams with the documentation they need to evaluate the service.
Data processing agreement
Published at /dpa — EU SCCs (Module Two) incorporated; Annex II prohibits model training on Customer Content.
Named subprocessors
The current named list within each Annex III category, furnished to security teams on request — 30 days' written notice before changes (DPA §6).
Security questionnaires
Questionnaires, DPAs, and vendor risk profiles answered at [email protected] within 3 business days.
security.txt
Security disclosures per RFC 9116, published at /.well-known/security.txt.
Need a deeper security review?
Quick questions answered the same business day; full questionnaires and vendor reviews within three business days.