Trust & Security

The data you’re trusted with, protected like it’s ours.

Management companies hold owner records, financials, governing documents, and board deliberations. Sliceo is built to protect all of it — with encryption, per-client isolation, affirmative consent for anything we record, and the plain commitment that your data is yours, never a product we sell or train on.

How we protect your data

Security built in, not bolted on.

Encrypted in transit & at rest

Every connection to Sliceo uses TLS, and data is encrypted at rest in our infrastructure. Where a product must hold a vendor login, it is encrypted with a key scoped to your firm alone.

Isolated per client

Each management company’s data is separated at the database layer. One client can never see another’s associations, owners, invoices, or reports — isolation is enforced on every request, not assumed.

Least-privilege access

Access to production data is limited to the people who need it, protected by multi-factor authentication, and logged. Your portal supports MFA and role-based access so you control who on your team sees what.

Hardened, global infrastructure

Sliceo runs on Cloudflare’s global network — the same infrastructure that fronts a large share of the internet — with DDoS protection, a managed web application firewall, and automatic patching at the edge.

Sandbox before live

Every integration we build is proven in an isolated sandbox before it ever touches your live platform, so “connected” never means “fragile.”

Continuous monitoring

Traffic, access, and click-over activity are logged and monitored so unusual behavior is visible quickly — and so your monthly reporting reflects exactly what happened on your account.

Your data is yours

We hold it. You own it.

Sliceo processes your data to run the products and services you’ve turned on — nothing else. We do not sell your data, we do not share it with advertisers, and we do not repurpose it for anything you didn’t ask for.

  • You own your data and can export it at any time.
  • We process it only for the purpose you gave it to us (purpose limitation).
  • A Data Processing Addendum (DPA) is available on request for GDPR/CCPA needs.
  • On termination, your data is returned or deleted on a defined schedule.

Retention & deletion

We keep data only as long as it serves the purpose you gave it to us, then delete it.

Recordings
Meeting recordings are destroyed once the minutes are complete — the transcript and approved minutes are what’s retained.
On request
Ask us to delete specific data and we’ll do it within a defined window, with clear notice of any legal-hold exceptions.
On termination
When you leave, your data is exported to you and removed from our systems on a stated schedule.
AI & meeting-recording consent

Minute Maker records with consent — never in secret.

Board meetings are sensitive, and recording laws vary by state. Minute Maker is built so recording is always visible, consented to, and used only to prepare your minutes.

Visible, never stealth

The notetaker joins as a clearly identified participant and posts a notice that the session is being recorded and transcribed for the sole purpose of preparing the minutes. It never hides.

Affirmative, all-party consent

Because remote attendees can span states with different laws, we default to all-party consent: everyone is notified and can decline, and the notetaker can be removed before executive session.

No training on your data

Your recordings, transcripts, and minutes are never used to train shared AI models by default. Your board’s deliberations are yours — not fuel for someone else’s product.

Purpose & retention disclosed

The consent notice states what is being recorded, why, how long it’s kept, and that it is not used for training — so nobody is agreeing to something hidden in fine print.

Honest deletion

The recording is destroyed once the minutes are complete. Deletion means deletion, within a stated window, with any legal-hold exceptions called out plainly.

Your brand, your control

Minute Maker ships under your management company’s brand, and your secretary approves every set of minutes before they’re filed. Sliceo stays invisible; you stay in control.

Subprocessors

A small, vetted set of vendors — disclosed.

To deliver Sliceo we rely on a short list of trusted infrastructure and service providers. We keep the list small, choose vendors with strong security postures, and disclose them. The current list is available on request, and we give notice before adding a subprocessor that would handle your data.

Categories include cloud infrastructure, payment processing, e-signature, transcription and AI, and email delivery. We’ll name the specific providers in our security summary and DPA.

Responsible disclosure

Found a security issue? We want to know, and we’ll work with you in good faith.

Email [email protected] with the details. We investigate promptly, keep you updated, and won’t pursue researchers who report in good faith and avoid harming data or privacy.

Questions or a vendor-security review?
We’re happy to complete security questionnaires and provide a DPA. Reach out and we’ll turn it around quickly.

Security questions before you commit?

Ask for our security summary, a DPA, or a walkthrough of how we’d protect your data — before anything touches your live platform.

Contact us about security