Security Architecture•Verified System Controls

Security engineered into every layer of our platform.

Executive presentations and strategy documents contain sensitive business information. We design DeckPilotAI with defense-in-depth principles from the ground up.

Strict Tenant Isolation

Every database query, attachment download, generation task, and WebSocket connection verifies tenant and project ownership. Cross-tenant leakage is architecturally blocked at the API gateway layer.

AES-256 Key Encryption

AI provider API keys and secrets are encrypted at rest using industry-standard AES-256 encryption. Keys are never logged, never exposed to browser runtimes, and never returned in API payloads.

Presigned Ephemeral Storage

Presentations and uploaded references are stored in Cloudflare R2 object storage. Files are accessible solely via short-lived, signed URLs that expire automatically after download.

Network SSRF Protections

All outbound provider and asset requests are validated by backend network security filters to block server-side request forgery (SSRF) and prevent access to private network ranges.

Magic-Byte Upload Validation

File uploads (PDF, DOCX, XLSX, TXT) undergo magic-byte verification, strict file size boundaries (25MB ceiling), and safe path sanitation before passing into extraction agents.

Zero Model Training

Customer documents, conversation prompts, and generated slides are strictly private. We never use or sell customer content to train foundation or public machine learning models.

Authentic Security Posture & Compliance Note

As an emerging AI technology startup, DeckPilotAI builds on security best practices from day one. We host our infrastructure on enterprise-grade Cloudflare and AWS environments and utilize Turso Edge databases with end-to-end TLS encryption.

In accordance with our commitment to transparency, we do not claim independent third-party certifications (such as SOC 2 Type II or ISO 27001) that have not yet been formally completed. As our enterprise offering expands, formal external compliance audits will be scheduled.