ISO 27001
Our information security management system is audit ready and certification work is underway. No certificate has been issued yet.
Security at Pretty
Pretty is built for teams whose presentations contain client, financial, and strategic information. You choose the deployment, storage, and AI endpoint. We document the controls behind each choice.
Assurance
Current controls and certification status, stated precisely enough for a first security review.
Our information security management system is audit ready and certification work is underway. No certificate has been issued yet.
Our contracts, controls, and processing model are designed around GDPR controller and processor obligations.
Every managed deployment component runs in EU regions. EU-hosted AI inference is available for managed deployments. Core managed application, database, and object-storage resources are configured in the EU. Authorized Sub-Processor transfers are listed in the DPA.
We do not use customer content to train AI models. The same restriction applies to the AI services contracted for Pretty workloads.
Deployment
Both deployment models preserve customer control over presentation content and AI-provider access. The difference is who operates the infrastructure.
Managed cloud
Every deployment component runs in EU regions. EU-hosted AI inference is available for managed deployments. Core application and storage resources are configured in Google Cloud Belgium.
Self-hosted
Dedicated deployment in your own cloud is available.
Security details
Customer data
Presentation files and source documents are stored when users upload or save them. Chat prompts and generated responses are retained as part of chat history.
Identity and access
Passwordless sign-in, organization roles, and tenant-scoped authorization protect user and workspace access.
Application security
Pretty separates organizations at the application and data layers and restricts production access to approved operational needs.
AI security
Pretty sends only the prompt and selected presentation context required for the user’s request to the configured endpoint.
Governance
Security and procurement teams can review the material behind the claims on this page before production rollout.
Resilience
The managed production service uses backups, monitoring, and documented incident and recovery procedures.
Legal documents
FAQ
For managed deployments, every deployment component runs in EU regions. EU-hosted AI inference is available for managed deployments. Core application, database, and object-storage resources are configured in Google Cloud europe-west1 in Belgium. Self-hosted customers choose and control their own location.
Presentation files and source documents are stored when users upload or save them. Chat prompts and generated responses are retained as part of chat history. Temporary processing copies created from uploaded content are automatically deleted after 14 days.
No. Pretty does not use prompts, presentations, uploaded files, or generated output to train AI models. Contracted AI services for Pretty workloads are also restricted from using that content for model training.
Yes. Pretty supports customer-provided OpenAI-compatible gateways, including LiteLLM. The customer controls the gateway, upstream models, credentials, logging, retention, and provider contracts.
SSO and SCIM provisioning are available upon request for enterprise deployments. We scope the identity-provider setup and provisioning flow with the customer before rollout.
Not yet. Pretty’s information security management system is audit ready and certification work is underway. An audit-readiness attestation is available upon request, but it is not an ISO certificate.
Customers can export data through available product functions. Pretty deletes stored customer data from active systems within the DPA timeline, and backup copies expire through the documented retention cycle.
Yes. The DPA, Sub-Processor details, technical and organizational measures, audit-readiness material, data flows, SLA, and security questionnaire responses are available for enterprise diligence.
Enterprise review
We can provide the documents, evidence, and deployment detail your security, privacy, and procurement teams need.
Start a security review