Security at Decky

Your presentations are company data. We treat them that way.

Decky is built for organizations that need AI without giving up control over their data, access, or presentation standards.

SOC 2 Type IISSORole-based accessEncryptionNo model training on customer data

Security at a glance

SOC 2 Type II certified

SAML SSO

Role-based access controls

Encryption in transit and at rest

Customer data not used to train models

Security FAQ

The answers your security team is looking for.

We know security reviews move fast. Here are the answers to the most common questions we get from enterprise teams.

Is our data used to train AI models?

No. Customer content is not used to train Decky or third-party foundation models.

Is our data encrypted?

Yes. All data is encrypted in transit (TLS 1.2+) and at rest using industry-standard protocols.

Can we control who gets access?

Yes. SSO, role-based permissions, and centralized administration give you full control.

Can Decky access our presentations?

Only authorized systems and personnel can access customer data according to defined operational controls.

What happens when data is deleted?

Customer data can be deleted at any time. Once deleted, it is removed from active systems and backups within 30 days.

Do you undergo third-party security reviews?

Yes. Decky is SOC 2 Type II certified with annual independent audits.

Security is built into everything we do.

We continuously monitor, test, and improve to keep your data safe.

View our security practices
Data + AI

Your company data stays your company data.

Decky uses your content only to provide the product, not to train models.

Your content

Presentations
Templates
Brand assets
Documents
Prompts
Company knowledge
D

Decky

Used only to provide the product

  • Access controls
  • Request orchestration
  • Policy enforcement
  • Audit & monitoring

AI providers

  • No model training
  • Controlled processing
  • Limited to what's required for the request

No training on customer data

Your data isn't used to train Decky's models or any third-party models.

Encryption in transit and at rest

Industry-standard encryption protects your data everywhere it goes.

Defined retention and deletion controls

You control what's kept, for how long, and when it's deleted.

Vendor and subprocessor oversight

We evaluate and monitor our partners to the same standards we hold ourselves to.

Built for enterprise AI adoption with clear data boundaries.

Transparent by design. Private by default. Trusted by enterprise teams.

05 — Security & Compliance

Built for enterprise security reviews.

The details your procurement and security teams expect, presented clearly.

Control areaSummary
SOC 2 Type II
Independently audited controls
Encryption
At rest + in transit
Authentication
SAML SSO
Access controls
Role-based permissions
Infrastructure
Secure cloud infrastructure
Backups & recovery
Documented backup and recovery process
Incident response
Documented security process
Penetration testing
Regular third-party testing

Need documentation for review?

SOC 2 reportDPASecurity questionnaireSubprocessor listRequest security package
VISIT THE TRUST CENTER

Everything your security team needs to move forward.

Access our security documentation in the Trust Center, or bring us into the conversation for anything your team needs.