Validation boundary: the public site has no upload form and does not request credentials, production data, or raw end-user data.
Default Handling Rules
- Access to customer materials limited to people with a business need.
- Strong authentication enabled for core systems where the provider supports it.
- No secrets, credentials, production databases, or raw end-user records requested by default.
- Customer materials stored only in approved workspaces.
- Redaction and minimization before AI-assisted processing where practical.
- Customer approval before sensitive materials are submitted to AI providers.
- Deletion or return process after pilot completion.
- No public customer reference without written approval.
Customer Material Boundaries
AssureDeck asks for the smallest useful evidence sample, prefers redacted examples, avoids credentials and secrets, and marks unsupported security claims as gaps instead of turning them into buyer-facing assurances.
AI Provider Approval Gate
Customer approval is required before sensitive pilot materials are submitted to an AI provider. If approval is not confirmed, AssureDeck uses a no-sensitive-data workflow.
DPA Readiness
If customer materials include personal data and AssureDeck processes it on behalf of the customer, a DPA or equivalent data-processing terms may be required.
- Subject matter and duration of processing.
- Nature and purpose of processing.
- Types of personal data and categories of data subjects.
- Customer instructions.
- Confidentiality, security, subprocessors, deletion/return, and audit support.
Incident Response Minimum
If a suspected incident affects customer materials, AssureDeck will contain access, preserve relevant logs, assess affected data, notify the owner, notify customers according to contract/DPA, avoid overstating facts before investigation, and document remediation.
Security Contact
Security reports can be sent to security@assuredeck.com.