Skip to content
No. 01 / Trust & security

What runs the site. What to allowlist. Where your data goes.

The page to forward to your IT team: one apex domain to allowlist, subprocessors documented by function, US data residency, and no model training on your content — ever.

Last updated: 2026-09-16

No. 02 / Controls

Security at every layer.

The controls your security team will ask about, in the order they ask.

Encryption in transit

TLS 1.3 preferred, TLS 1.2 minimum — modern cipher suites only. Every subdomain is HTTPS-only (HSTS).

Encryption at rest

AES-256 on the database and on object storage.

Data residency

United States (US-East). Data at rest and compute are US-only; EU transfers ride the SCCs incorporated into our DPA.

No model training

Never on your briefs or decks — contractually prohibited at every LLM and voice-agent vendor (DPA Annex II).

No. 03 / Data lifecycle

Know what happens to the material you provide.

Deletion is self-serve — /app/settings → Delete account cascades to all owned briefs and decks. What we never do is documented just as plainly.

Scheduled immediately with a 24-hour cancel window; cascaded and hard-purged from primary storage within 30 days
Encrypted backups retained up to 35 days, then destroyed
No selling, sharing, or renting personal data to advertisers — GPC and DNT honored
No third-party browser trackers on app.askdeck.ai — first-party analytics only
No PHI: we are not a HIPAA Business Associate — do not put PHI in a brief
We never see card data — a PCI-DSS Level 1 processor handles all payment instruments
Deletion timeline
1.Delete account — /app/settings✓ Scheduled
2.Cancellation window✓ 24 hours
3.Cascade to owned briefs and decks✓ After 24 h
4.Hard-purge from primary storage✓ ≤ 30 days
5.Encrypted backups destroyed✓ ≤ 35 days
No. 04 / For your IT team

One wildcard covers everything.

Allowlist *.askdeck.ai under Business / Productivity / SaaS — all subdomains are HTTPS-only and TLS-only (HSTS).

Wildcard

*.askdeck.ai

One entry covers the marketing site, the app, and the API. Category requested: Business / Productivity / SaaS.

Marketing

askdeck.ai · www.askdeck.ai

The public site — this page included.

App

app.askdeck.ai

The authenticated workspace: deck library, brief form, brand kit.

API

api.askdeck.ai

HTTPS REST, plus live deck-build progress on a long-lived HTTPS response over port 443 — no WebSocket. Proxies that cut idle connections only make the progress view reconnect; generation completes on the server.

MCP

mcp-api.askdeck.ai

The public MCP server — Claude, Cursor, ChatGPT and other MCP clients connect here. OAuth only; no credential is ever pasted into the client.

Blog

blog.askdeck.ai

The AskDeck blog, linked from Resources.

Suggested email

If askdeck.ai is blocked on your corporate network, the fastest path is someone on the inside asking IT for an exception — most allowlist requests are resolved within 24 hours when they come from a verified employee.

Hi — I'm trying to access askdeck.ai, an AI-powered tool that drafts editable PowerPoint decks from a short brief. Could you allowlist *.askdeck.ai under the Business / Productivity / SaaS category? The vendor's full security posture — subprocessors, encryption, data residency, deletion — is published at https://askdeck.ai/trust. If you need a security questionnaire, DPA, or vendor risk profile, the vendor responds at security@askdeck.ai within 3 business days.

No. 05 / Subprocessors

Every third party that touches your data, by function.

The categories are set out in Annex III of our DPA; request the current named list for your security team. We give 30 days' written notice before adding or replacing a subprocessor (DPA §6).

Subprocessors — categories per DPA Annex III
FunctionProvider (by category)Data received
Hosting (compute)Cloud compute provider — United StatesService traffic + ephemeral runtime state
DatabaseManaged relational database — United States, encrypted at restAccounts, briefs, decks, billing records
Object storageObject storage — United States, encrypted at rest.pptx files, audio recordings, brand-kit assets
Edge / CDN / DNSCDN / edge-security providerTraffic metadata + IP addresses
AuthenticationIdentity provider — passwordless / OAuthEmail + authentication identifiers (no passwords stored by us)
PaymentsPCI-DSS Level 1 payment processorBilling details + card data (the processor receives it; we do not)
LLMEnterprise LLM providerBrief text; contractually no model training on customer data
VoiceTelephony provider — inbound calls + voice agentPhone numbers, call audio
SMS / iMessage / RCSMessaging providerPhone numbers, message content, delivery receipts
Voice agent runtimeSpeech-to-text + voice-agent runtime providerCall audio + transcripts
Transactional emailTransactional email provider — outbound + inbound parsingEmail addresses + message contents
Webhook deliveryWebhook delivery providerWebhook payloads sent to customer endpoints
Product analyticsFirst-party product analytics, served from our own domainPage-view + click events; opt-in session replay; GPC honored

All processing is performed in the United States. EU customers: international transfers are governed by the EU SCCs incorporated into our DPA (Module Two).

No. 06 / Web-gateway categorization

Still showing as Uncategorized?

We've requested categorization with the major secure web gateways. Your IT can re-query the database or submit a recategorization request — most vendors honor it within 1–3 business days. Submission receipts on request.

Palo Alto Networks PAN-DB

urlfiltering.paloaltonetworks.com

Symantec / Broadcom WebFilter

sitereview.bluecoat.com

Fortinet FortiGuard

fortiguard.com/webfilter
No. 07 / Contacts

One inbox per topic.

Quick security questions answered the same business day; full questionnaires and vendor reviews within three business days.

Security & vendor reviewsecurity@askdeck.ai
AI deck intake (email)eric@askdeck.ai
AI deck intake (SMS / iMessage)+1 (743) 256-5873By texting AskDeck at this number you agree to receive conversational and transactional messages from AskDeck about your deck request. Msg frequency varies. Msg & data rates may apply. Reply STOP to cancel, HELP for help. TermsPrivacy
Security disclosures (RFC 9116)/.well-known/security.txt
No. 08 / Procurement

Enterprise review materials.

Provide procurement and security teams with the documentation they need to evaluate the service.

Data processing agreement

Published at /dpa — EU SCCs (Module Two) incorporated; Annex II prohibits model training on Customer Content.

Named subprocessors

The current named list within each Annex III category, furnished to security teams on request — 30 days' written notice before changes (DPA §6).

Security questionnaires

Questionnaires, DPAs, and vendor risk profiles answered at security@askdeck.ai within 3 business days.

security.txt

Security disclosures per RFC 9116, published at /.well-known/security.txt.

Need a deeper security review?

Quick questions answered the same business day; full questionnaires and vendor reviews within three business days.