Security & Trust
Last updated: October 1, 2026
PresaleIQ handles discovery-call transcripts, client requirements and platform credentials. This page summarises how we protect that data so your IT, security and procurement teams can approve PresaleIQ as a sanctioned tool — not shadow IT. For a completed security questionnaire, a DPA, or a call with the founder, email support@presaleiq.ai.
Hosting & infrastructure
- Production runs on Amazon Web Services (region us-east-2, Ohio, USA) on encrypted-at-rest storage.
- All traffic is served over HTTPS/TLS (Let's Encrypt certificates, auto-renewed) with HTTP Strict Transport Security.
- Administrative access is limited to the founder via SSH key; no password logins to servers.
- Changes are tested on a separate staging environment before production deployment.
Tenant isolation
- Shared SaaS: every organisation's data is logically isolated; queries are scoped to the signed-in user's organisation and role.
- Dedicated instance: available on request — your own subdomain, database, application secret and process, with no vendor super-admin account inside it.
- Self-hosted (On-Prem Edition): run PresaleIQ in your own infrastructure via Docker, with full control of the database and storage.
Identity & access
- SAML 2.0 single sign-on (Okta, Microsoft Entra ID, Auth0 and other SAML IdPs) with just-in-time user provisioning.
- Sign in with Google, Microsoft or LinkedIn, or email + password (hashed, never stored in plain text) with email verification.
- Role-based access control: Member, Manager and delegated administrator roles.
- Brute-force protection on sign-in, CSRF protection on every form, and Secure/HttpOnly session cookies.
Data protection
- Configurable retention per organisation: None (transcript and raw AI output scrubbed after delivery — the default for self-serve trials), Analyses only, or Full.
- Credentials for connected platforms (ServiceNow, Jira, Salesforce, etc.) are encrypted with Fernet (AES-128 + HMAC) using a key held outside the database.
- No training on your data. PresaleIQ uses Anthropic's Claude through Anthropic's commercial API, whose terms prohibit Anthropic from training models on customer content. PresaleIQ does not train models on your data either.
- Every analysis and platform push is time-stamped against the user who performed it.
Sub-processors
We use the following third parties to deliver the service. We will update this list before adding a new sub-processor that processes customer content.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Amazon Web Services | Application hosting; transactional email (SES) | All service data; email addresses | USA |
| Anthropic, PBC | AI analysis (Claude API) | Transcripts, documents and prompts you submit | USA |
| Recall.ai | Meeting bot & transcription for the live meeting agent (only if you use it) | Meeting audio and transcript | USA |
| Resend | Transactional email delivery | Email address, delivered documents | USA |
| PayPal | Subscription billing | Billing contact and payment details (we never see card numbers) | USA |
| Google, Microsoft, LinkedIn | Optional social sign-in | Name, email, profile identifier | USA |
Responsible AI
- Generated User Stories, SOWs, estimates and designs are drafts for a qualified human to review before they are sent to a client or pushed to a platform.
- Direct platform push only runs when a user explicitly triggers it, against a connection your administrator configured.
Reporting a vulnerability
Please email support@presaleiq.ai. We acknowledge reports within 2 business days and ask that you give us reasonable time to fix an issue before disclosing it.