PREZENTDCompliance Summary
Security & compliance, on one page.
A diligence summary advisors can hand to their OSJ or compliance department. Every statement below is current; the authoritative source documents — SOC 2 Type II report, System Description, and policies — live in the Trust Center linked at the bottom.
- Product
- PREZENTD — the deliverable workspace where an advisory firm's sales motion lives.
- Operated by
- CW Frontier Innovations LLC. PREZENTD is one of three products on the same audited platform and shared infrastructure vendors.
- SOC 2 Type II
- PREZENTD is built on the CW Frontier Innovations platform, which maintains SOC 2 Type II compliance, with PREZENTD in scope of the audit and real-time monitoring via Vanta. The SOC 2 Type II report and System Description are available in the Trust Center under NDA.
- No model training
- Customer content is not used to train AI models. Customer-content AI requests run on zero-data-retention routing with data collection denied; providers do not retain prompts or responses.
- Gateway guardrails
- Before customer content reaches a model, the AI gateway applies prompt-injection detection and redaction for common sensitive-data patterns (SSNs, card numbers, IP addresses).
- Nothing raw stored
- PREZENTD does not store prompts, model reasoning, or raw model output. Operational logs carry identifiers, counts, cost, and latency only.
- United States
- Application hosting, database, and file storage are in the United States.
- Who can access firm data
- Access is restricted to authenticated members of the firm's own workspace, governed by organization-scoped controls and database-level (row-level security on every customer table) tenant isolation. Authentication is handled by Clerk with Google and Microsoft sign-in; admin and member roles with seat limits per plan. Client content is not used for model training or shared with third parties beyond the zero-data-retention AI providers required to deliver the service.
- Uploaded files
- Files uploaded to a build are kept as governed Sources the firm owns: an encrypted copy of the original, scoped to the firm and visible on the client's page. Any file can be excluded by unticking Keep before it uploads, and any Source can be deleted by the customer at any time; deletion removes the file and everything extracted from it.
- Meetings & Firm Memory
- Source retention is tied to the Meetings & Firm Memory feature. Meeting transcripts the firm adds are retained until the firm deletes them. With the feature turned off, uploads revert to extract-and-discard: the extracted text is used for the single deliverable and the file is deleted.
- Meeting Reports & Client Profiles
- Internal documents. They have no share link, are never client-facing, and can only be emailed to members of the firm's workspace.
- Export & deletion
- Customers can export their deliverables at any time. On cancellation, workspace data — including retained Sources and transcripts — is deleted on request, with no extended holding window.
- Within 72 hours
- A defined incident-response process; affected customers are notified within 72 hours of a confirmed breach affecting their data, with the information needed for the firm's own regulatory obligations.
- What is genuinely AI
- LLMs draft narrative, build deliverables, write Meeting Reports and Client Profiles, and apply firm voice. Duplicating a template, editing text in place, and applying the brand are deterministic and never call a model. Adapting a template with AI does, on zero-data-retention routing.
- Human in the loop
- PREZENTD drafts and assembles deliverables; it does not send anything to clients and does not perform financial calculations or make recommendations. Every client-facing deliverable passes through advisor review and approval. The firm remains responsible for review, supervision, and recordkeeping under its own policies.
- Encryption
- Customer data is encrypted in transit and at rest across production infrastructure and managed storage.
- Client links
- Shared presentation links (Pro and Team) use encrypted tokens, expire 30 days after creation, can be revoked or regenerated at any time, render a fixed snapshot, and are served with no-cache, no-index, and no-referrer protections. Advisor approval is required before a link or PDF exists.
- Version history
- Every deliverable keeps a full version history with a timestamp and the user who made each change.