Security

Your documents, brand assets, and presentation data are handled with strict security controls. Here is exactly how we protect your information.

Data handling

Document and brief data

  • Documents uploaded for deck generation are processed in isolated environments
  • Input data is used solely for generating your requested presentation
  • Processed documents are not retained after deck generation completes
  • No input data is used to train or improve AI models

Brand asset storage

  • Brand kits (logos, color definitions, font specifications) are stored encrypted at rest
  • Assets are accessible only to authenticated members of your workspace
  • Deletion of brand assets is immediate and permanent upon request
  • Brand data is stored in geographically appropriate data centers

Encryption

In transit

All data transmitted between your browser and SHINEVISH servers is encrypted using TLS 1.3. API communications use the same encryption standard.

At rest

Stored data including generated decks, brand assets, and account information is encrypted at rest using AES-256 encryption with managed keys.

Access control

Authentication

Email-based authentication with secure session management. Multi-factor authentication available for Team and Agency plans.

Workspace isolation

Team and Agency workspaces are logically separated. Members can only access decks and assets within their own workspace.

Role-based permissions

Workspace administrators control who can manage brand kits, create decks, and invite new members.

Data retention

Data typeRetention period
Input documents (briefs, uploads)Deleted after generation completes
Generated presentationsRetained while account is active
Brand kit assetsRetained until manually deleted
Account dataRetained while account is active, deleted 30 days after closure
Usage analytics (aggregated)Retained for product improvement, no PII

Compliance posture

SHINEVISH implements security controls aligned with industry standards. Our infrastructure runs on cloud providers that maintain SOC 2 Type II, ISO 27001, and GDPR compliance certifications.

We are transparent about our current compliance status: we follow security best practices and leverage certified infrastructure, while working toward our own formal certifications as the platform matures.

Security questions?

If you have specific security requirements or questions about how we handle your data, reach out directly.

Contact Us