The pilot went well. The team loves the tool; it's cutting hours off deck production, and the champion inside the firm wants to roll it out to 200 people. Then it hits procurement and security review, and the questions start. Where does our data go? Does it train on our slides? Is there a signed DPA? Can we get the SOC 2 report? And suddenly the tool everyone loved is stuck in a queue behind a security questionnaire nobody can answer.

For consulting firms and investment banks, this is where most AI tool purchases live or die. The slides your teams build contain client names, deal figures, unannounced transactions, and strategic analysis that is legally and commercially sensitive. An AI PowerPoint tool touches all of it. So, the security bar isn't a formality. It's the actual gate.

This blog gives you the exact questions to ask any AI PowerPoint vendor before you sign, organized by what each certification proves, plus where auxi stands on each one, so you can see what a complete answer looks like.

Why PowerPoint Tools Are a Bigger Data Risk Than They Look

It's easy to think of a slide tool as low risk. It's "just formatting." But the deck is often the single most sensitive artifact in the engagement. A pitchbook can contain a target company's name before the deal is public. A strategy deck can contain a client's confidential three-year plan. A diligence summary can contain financials under NDA.

When an AI tool processes that deck, the questions that matter are the same ones you'd ask of any data processor handling regulated information: where does the data go, who can see it, how long is it kept, is it used to train models, and can you prove any of it.

I. What SOC 2 Actually Proves (and What to Ask)

SOC 2 is an independent audit of a vendor's controls across security, availability, processing integrity, confidentiality, and privacy. It is not a law. It's the de facto B2B trust standard, and enterprise buyers increasingly won't sign without it. But "we're SOC 2" is a claim, not evidence, so ask for specifics.

Ask these:

  1. Are you SOC 2 certified, and can you share the report under NDA? A vendor should be able to produce the actual report, not just claim the badge.
  1. Is it Type I or Type II? Type I checks that controls exist at a single point in time. Type II checks that they operated effectively over a period, usually 6 to 12 months. Type II is the stronger standard for enterprise deployment.
  1. When was the last audit?  Ask for the current cycle.
  1. Who performed it? Independent third-party auditors are the point. Self-attestation is not SOC 2.

Where auxi stands: auxi is SOC 2 certified and supports the full IT and security assessment process enterprise buyers run, alongside regular external audits. auxi's platform security is independently audited, including protection by SECTIGO and A+ scores in regular reviews by external auditors such as ASTRA. For the actual report and audit details, the enterprise team walks security reviewers through the documentation directly.

II. What GDPR Compliance Actually Proves (and What to Ask)

If any of your data concerns EU residents, or you operate in the UK or other GDPR-adjacent jurisdictions, your AI PowerPoint vendor is a data processor under the regulation. That creates concrete obligations, and a compliant vendor should be able to speak to each one without hesitation.

Ask these:

  1. Will you sign a Data Processing Agreement? You need a signed DPA before a vendor can legally process personal data on your behalf. If they hesitate here, stop.
  1. Where is data stored and processed? Data residency matters under GDPR. Ask specifically where your slides and any personal data within them live.
  1. What's your retention and deletion policy? How long is data kept, and can you request deletion? A processor should support data subject rights.
  1. Who are your sub-processors? If the tool routes anything through third-party AI models, those providers are sub processors, and you need to know who they are and what they do with the data.

Where auxi stands: auxi is GDPR compliant, with data protection and system integrity confirmed through external audit. GDPR support is part of the standard enterprise IT and security assessment, alongside custom deployment options for firms with specific compliance needs.

III. The Question Most Buyers Forget: Does It Train on Your Data?

This is the AI-specific question that standard SaaS security reviews are not built to catch, and it's the one that matters most for a firm whose slides are its intellectual property.

When an AI tool processes your deck, that content may pass through a language model. Depending on the vendor and the model, your data may be used for training, logged for quality review, or retained after the interaction. For a firm handling confidential client work, "your slides may be used to train our models" is often a hard no.

Ask these:

  1. Is our content used to train your models, ever? Get this in writing.
  1. If you train on customer data, is it opt-in, and is it obfuscated? Some vendors train only on anonymized, obfuscated data with permission. That's a very different posture from training on raw client slides.
  1. What happens to our data after processing? Retention and logging policies for AI operations specifically, not just general storage.

Where auxi stands: auxi does not have its own models and does not train on your data. At onboarding, auxi's Slide Collection Process collects and obfuscates your templates as a one-time setup step to save those slides' settings, not for model training. For the specifics, your security team can walk through the process directly with auxi's enterprise team.

auxi meets the enterprise side of this checklist directly, with SOC 2, SSO, GDPR, and HIPAA support built into its standard security assessment and custom deployments available for firms with specific compliance needs.

Run your security review with auxi's enterprise team. Request a demo.