Trust Center

Resource library

Our security, compliance, and policy documentation, including audit reports.

SOC 2 Type II Report - 2025

No description available.

Feb 2026

PCI DSS - Letter of Engagement

No description available.

Apr 2026

Vulnerability Assessment and Penetration Testing (VAPT) Report

No description available.

Jun 2026

Business Continuity and Disaster Recovery Policy

Establishes plans for maintaining operations during outages or crises, and outlines recovery procedures to restore systems and services with minimal disruption.

Jun 2026

Information Security Policy

Establishes the framework for managing and protecting sensitive information assets, ensuring confidentiality, integrity, and availability.

Jun 2026

Incident Response Plan and Policy

Outlines how the organization detects, reports, investigates, and responds to security incidents to minimize impact and support recovery and compliance obligations.

Jun 2026

Information Security Roles and Responsibilities Policy

Defines the roles and responsibilities for information security within the organization, ensuring accountability and effective management of security risks.

Jun 2026

Code of Conduct

Defines acceptable behaviors and responsibilities for all employees to ensure a respectful and inclusive workplace.

Jun 2026

Access Management Policy

Describes how user access to systems and data is provisioned, reviewed, and revoked based on roles and business needs, following the principle of least privilege.

Jun 2026

Enterprise Risk Management Policy

Establishes a framework for managing risks to the organization's operations, assets, and individuals.

Jun 2026

Software Development Policy

Establishes guidelines for secure software development practices, including coding standards, code reviews, and security testing.

Jun 2026

Vendor Risk Management Policy

Establishes a framework for managing risks associated with third-party vendors, including risk assessment, due diligence, and ongoing monitoring.

Jun 2026

PCI DSS Control Standard

This standard documents the control objectives, technical configurations, and operational procedures used to implement and maintain compliance with PCI DSS.

Jun 2026

Artificial Intelligence Management Policy

This Artificial Intelligence Management Policy (the “Policy”) establishes the Artificial Intelligence Management System (the “AIMS”) for products designed, created and implemented by Deck that use artificial intelligence.

Jun 2026

Acceptable Use Policy

This policy specifies acceptable use of end-user computing devices and technology.

Jun 2026
Powered by