Decked
  • How it works
  • Try it
  • Pricing
  • For agencies
  • About
Log in Get started
Legal

Security

Last updated: April 2025

Security is not a feature we add later. It is a constraint we build around from the start. Here is how we protect data on the Decked platform.

Data transmission

All data transmitted between your browser and Decked is encrypted using TLS 1.2 or higher. This applies to homeowner consultations, contractor accounts, uploaded photos, and all API traffic. We do not serve content over unencrypted HTTP.

Data storage

Consultation data, photos, and account information are stored on encrypted infrastructure. Encryption keys are managed separately from the data they protect. Backups are encrypted at rest and tested regularly.

Access controls

Contractor account access is protected by password authentication. We enforce minimum password strength requirements. Access to production systems is restricted to engineering staff who require it and is logged. We use the principle of least privilege throughout our infrastructure.

Photo and file uploads

Room photos uploaded during consultations are transmitted directly to encrypted storage. They are accessible only to the contractor associated with the consultation and to Decked staff for support purposes. Photos are not used for any purpose other than delivering the consultation package.

Payment security

We do not store credit card numbers. Payment processing is handled by a PCI-compliant third-party provider. Decked never has access to your full card details.

AI and generated content

Consultation data used to generate visualizations is transmitted to AI providers under data processing agreements that restrict its use to generating your output. Consultation content is not used to train models.

Vulnerability disclosure

If you discover a security vulnerability in Decked, please report it to [email protected]. We ask that you give us reasonable time to investigate and address the issue before public disclosure. We do not pursue legal action against good-faith security researchers.

Incident response

In the event of a security incident that affects your data, we will notify affected account holders within 72 hours of confirming the incident. Notifications will include what happened, what data was affected, and what steps we have taken.

Questions

Security questions or concerns? Email [email protected].

Decked

We put contractors on the field ready to score. Starting in renovation. Moving toward every high-ticket physical project in the world.

Product
  • How it works
  • Pricing
  • For agencies
  • Book a demo
Company
  • About
  • Investors
  • Blog
  • Careers
Legal
  • Privacy policy
  • Terms of service
  • Security