Pretty

Security at Pretty

Security that keeps your decks under your control.

Pretty is built for teams whose presentations contain client, financial, and strategic information. You choose the deployment, storage, and AI endpoint. We document the controls behind each choice.

Assurance

The status, without the fine print.

Current controls and certification status, stated precisely enough for a first security review.

ISOAudit ready

ISO 27001

Our information security management system is audit ready and certification work is underway. No certificate has been issued yet.

GDPRDesigned for GDPR

GDPR

Our contracts, controls, and processing model are designed around GDPR controller and processor obligations.

EUEU deployment

EU data residency

Every managed deployment component runs in EU regions. EU-hosted AI inference is available for managed deployments. Core managed application, database, and object-storage resources are configured in the EU. Authorized Sub-Processor transfers are listed in the DPA.

AIContractual control

No model training

We do not use customer content to train AI models. The same restriction applies to the AI services contracted for Pretty workloads.

Deployment

Choose where Pretty runs.

Both deployment models preserve customer control over presentation content and AI-provider access. The difference is who operates the infrastructure.

Managed cloud

Pretty operates the stack in Europe.

Every deployment component runs in EU regions. EU-hosted AI inference is available for managed deployments. Core application and storage resources are configured in Google Cloud Belgium.

  • Managed hosting, monitoring, backups, and recovery
  • Customer-controlled AI endpoints and provider credentials
  • Paid-production SLA and security evidence on request
  • SSO and SCIM provisioning available upon request

Self-hosted

Bring your own cloud:

Dedicated deployment in your own cloud is available.

  • Compute, storage, and egress under your control
  • Architecture and code path available for review
  • Designed for regulated and restricted environments

Security details

The controls behind the claims.

Customer data

You decide what Pretty keeps.

Presentation files and source documents are stored when users upload or save them. Chat prompts and generated responses are retained as part of chat history.

  • Temporary processing copies created from uploaded content are automatically deleted after 14 days.
  • Authorized staff may access chat content through restricted support and monitoring systems.
  • Stored content can be deleted through product and contract-exit workflows.
  • Customer content is not used for model training.

Identity and access

Access follows the organization.

Passwordless sign-in, organization roles, and tenant-scoped authorization protect user and workspace access.

  • Owner, administrator, and member roles
  • SSO and SCIM provisioning are available upon request.
  • Staff multi-factor authentication and least privilege
  • Periodic access review and logged privileged operations

Application security

Controls cover data in motion and at rest.

Pretty separates organizations at the application and data layers and restricts production access to approved operational needs.

  • TLS encryption in transit and encryption at rest
  • Row-level tenant isolation and scoped authorization
  • Managed secrets and separated environments
  • Dependency, vulnerability, and change controls

AI security

Model access stays under contract.

Pretty sends only the prompt and selected presentation context required for the user’s request to the configured endpoint.

  • Customer-provided LiteLLM and OpenAI-compatible gateways supported
  • Customer controls upstream models, credentials, and retention choices
  • EU-hosted AI inference is available for managed deployments.
  • No prompt or output training by Pretty

Governance

Evidence is available for diligence.

Security and procurement teams can review the material behind the claims on this page before production rollout.

  • DPA, Standard Contractual Clauses, and Sub-Processor information
  • Technical and organizational measures
  • Audit-readiness attestation and security questionnaire responses
  • Data-flow and deployment documentation

Resilience

Production recovery has defined objectives.

The managed production service uses backups, monitoring, and documented incident and recovery procedures.

  • Automated backups at least daily
  • At least 30 days of backup retention
  • 24-hour recovery point objective
  • 12-business-hour recovery time objective for qualifying failures

FAQ

Common security questions.

Where is Pretty hosted?

For managed deployments, every deployment component runs in EU regions. EU-hosted AI inference is available for managed deployments. Core application, database, and object-storage resources are configured in Google Cloud europe-west1 in Belgium. Self-hosted customers choose and control their own location.

Does Pretty store presentation content?

Presentation files and source documents are stored when users upload or save them. Chat prompts and generated responses are retained as part of chat history. Temporary processing copies created from uploaded content are automatically deleted after 14 days.

Does Pretty use customer data to train AI models?

No. Pretty does not use prompts, presentations, uploaded files, or generated output to train AI models. Contracted AI services for Pretty workloads are also restricted from using that content for model training.

Can we use our own AI provider or gateway?

Yes. Pretty supports customer-provided OpenAI-compatible gateways, including LiteLLM. The customer controls the gateway, upstream models, credentials, logging, retention, and provider contracts.

Are SSO and SCIM supported?

SSO and SCIM provisioning are available upon request for enterprise deployments. We scope the identity-provider setup and provisioning flow with the customer before rollout.

Is Pretty ISO 27001 certified?

Not yet. Pretty’s information security management system is audit ready and certification work is underway. An audit-readiness attestation is available upon request, but it is not an ISO certificate.

What happens when our contract ends?

Customers can export data through available product functions. Pretty deletes stored customer data from active systems within the DPA timeline, and backup copies expire through the documented retention cycle.

Can our security team review more evidence?

Yes. The DPA, Sub-Processor details, technical and organizational measures, audit-readiness material, data flows, SLA, and security questionnaire responses are available for enterprise diligence.

Enterprise review

Bring us your security requirements.

We can provide the documents, evidence, and deployment detail your security, privacy, and procurement teams need.

Start a security review