Skip to content

Draft pending counsel review — last updated 2026-09-29. This is a working draft published for transparency. It is not final legal advice and will change after review.

Security

What we actually do to protect your work. We list controls only when they are part of how the service is built.

Controls in place

Tenant isolation

Every read and write of project content is scoped to the owning account, and authorisation is checked on every source, export, audio chunk, assessment, share link and signed-URL issuance. Knowing a file’s content hash never grants access to it. Private prompts, evidence and generated narration are not cached across customers.

Encryption in transit

All traffic to slidedeck.my and between our services and providers uses TLS.

Private storage

Uploaded files, exports and any opted-in recordings are stored in private Cloudflare R2 buckets with no public access. Files are served only through authorisation-checked requests or short-lived signed links.

Passwordless sign-in

You sign in with a magic link or a one-time email code. Codes expire after 5 minutes and allow a limited number of attempts; sign-in requests are rate limited and responses don’t reveal whether an account exists. Magic links use a confirmation step so email security scanners can’t consume them.

Redacted logs

Logs record identifiers and diagnostic classifications, never document text, prompts, transcripts, audio or secrets. General security logs have a 30-day working retention.

Safe handling of sources

  • URL fetching is guarded against server-side request forgery (no access to internal or private network addresses).
  • Document macros and external-resource resolution are disabled when parsing uploads.
  • User-supplied or AI-produced code is never executed as part of a slide.
  • Text in your sources is treated as data, not as instructions to the AI.

Secrets and payments

Provider keys are held in managed secret storage, not in code. Card details are handled by Stripe; we never see or store full card numbers.

Support access

Support access to account data is scoped, time-limited, consented where needed, and audited.

Certifications

SlideDeck does not currently hold SOC 2, ISO 27001 or any other security certification, and we won’t claim one until an audit is complete. Our infrastructure providers maintain their own certifications, which don’t transfer to us.

Report a vulnerability

Email security@slidedeck.my with a description, steps to reproduce, and the affected URL or component. Please:

  • test only against your own account and data;
  • avoid privacy violations, data destruction and service disruption;
  • give us reasonable time to fix the issue before disclosing it.

We will acknowledge your report, keep you updated, and credit you if you wish. We will not pursue good-faith research that follows these guidelines (safe-harbour wording subject to counsel review). We don’t currently run a paid bug bounty.

Incidents

If an incident affects your data, we will notify you and the relevant authorities as the law requires. Operational incidents are posted on the status page with time and scope. Incident contact: security@slidedeck.my.