Back to AssureDeck

Security and data handling

Security Posture

This page describes the minimum handling rules AssureDeck applies to prospect data and paid-pilot materials during validation.

Validation boundary: the public site has no upload form and does not request credentials, production data, or raw end-user data.

Default Handling Rules

  • Access to customer materials limited to people with a business need.
  • Strong authentication enabled for core systems where the provider supports it.
  • No secrets, credentials, production databases, or raw end-user records requested by default.
  • Customer materials stored only in approved workspaces.
  • Redaction and minimization before AI-assisted processing where practical.
  • Customer approval before sensitive materials are submitted to AI providers.
  • Deletion or return process after pilot completion.
  • No public customer reference without written approval.

Customer Material Boundaries

AssureDeck asks for the smallest useful evidence sample, prefers redacted examples, avoids credentials and secrets, and marks unsupported security claims as gaps instead of turning them into buyer-facing assurances.

AI Provider Approval Gate

Customer approval is required before sensitive pilot materials are submitted to an AI provider. If approval is not confirmed, AssureDeck uses a no-sensitive-data workflow.

DPA Readiness

If customer materials include personal data and AssureDeck processes it on behalf of the customer, a DPA or equivalent data-processing terms may be required.

  • Subject matter and duration of processing.
  • Nature and purpose of processing.
  • Types of personal data and categories of data subjects.
  • Customer instructions.
  • Confidentiality, security, subprocessors, deletion/return, and audit support.

Incident Response Minimum

If a suspected incident affects customer materials, AssureDeck will contain access, preserve relevant logs, assess affected data, notify the owner, notify customers according to contract/DPA, avoid overstating facts before investigation, and document remediation.

Security Contact

Security reports can be sent to security@assuredeck.com.