Presenting Confidential Content: Data Protection for Board Meetings

Keep board presentations confidential: what should never leave your device and how to check where a tool sends data.

Cliqer Team

20 September 2026 · 6 min read

A boardroom table with a laptop showing an abstract blurred chart, empty chairs waiting for a meeting to begin

A board deck is one of the most sensitive documents most organisations produce: unreleased financials, acquisition talk, restructuring plans, things that move markets or careers if they leak early. Yet the tool used to present it often gets less scrutiny than the tool used to book the meeting room. Data protection for board meetings deserves the same rigour applied to the numbers themselves, and it starts with a question most people never ask: where does the deck actually go once you hit present?

This is a practical guide to that question, written for the people who have to answer it before the next board meeting, not after something goes wrong.

Key takeaways
  • The strongest protection is architectural: content that is never uploaded cannot be exposed in a breach.
  • Cliqer's desktop app drives your presentation software locally, so slides are never uploaded to a server.
  • Control who is in the room too, invite-only access, host removal, and SSO or team roles for scheduling rights.

The question nobody asks until it is too late

Most presentation and screen-sharing tools upload your content to a server somewhere before displaying it to viewers. That is not necessarily malicious, it is often just the easiest way to build a screen-sharing feature, but it means your board deck sits on infrastructure you do not control, for however long the vendor's retention policy says it does.

For most presentations, that is a manageable risk. For a board deck, an M&A discussion or unreleased results, it is worth asking directly: does this tool ever store our content, and if so, where and for how long? The answer decides whether your exposure ends when the meeting ends, or continues quietly on someone else's server long after everyone has closed their laptops.

Ask a vendor this exact question in writing: "if your service were breached tomorrow, would our presentation content be among the data exposed?" A confident "no, we never store it" is a very different answer than a paragraph about encryption at rest.

What "never leaves your device" actually means

The strongest answer to that question is architectural, not procedural: content that is never uploaded cannot be exposed in a breach of the presentation tool, full stop. That is the model Cliqer's desktop app uses. The app drives your presentation software, PowerPoint, Keynote, Google Slides and others, directly on the computer showing the slides. Slide-advance commands, pointer positions and any screen or camera stream travel over encrypted WebRTC directly between participants, or through an encrypted relay on restrictive networks. The slides themselves are never uploaded to a server.

That distinction is worth spelling out for a board or legal team: it is not that the content is encrypted while stored, it is that there is no copy stored to encrypt in the first place.

What does travel, and how it is protected

Nothing is presented in a vacuum. Some data does move between the room coordination layer and participants, and it is worth knowing exactly what:

WhatWhere it goesProtection
Room ID, display names, presenceSignaling serverTLS (WSS)
Slide commands, pointer position, timer stateDirectly between devices, or relayedDTLS, encrypted end to end
Screen or camera streams, if enabledDirectly between devices, or relayedSRTP, encrypted end to end
Session chatDirectly between devicesText-only, peer to peer, never stored
Account and licence recordsCliqer's account platformTLS, stored, standard SaaS data

The full breakdown, built specifically for security review, is in the data flow diagram, which also covers what is transient versus what is stored.

Controlling who is in the room

Content protection is only half the job. The other half is making sure the right people, and only the right people, are in the room at all.

  • Access is by invite. A room is joined with a specific link or code, not a public listing.
  • The host sees every participant and can remove or block anyone during the session.
  • For teams with formal access requirements, team roles and SSO control who inside your organisation can even schedule or run a board session in the first place.

For a board specifically, it is worth combining this with a simple internal rule: only named, expected attendees join the actual session link, and anyone else gets a recording or a written summary afterwards instead of the live link itself.

Building this into your governance process

If your organisation has a formal IT or security review for new tools, board-level presentations are exactly the use case that should trigger one, even if the tool is already in use elsewhere for lower-stakes meetings. Our guide to getting AV software approved by IT walks through that process, and the security checklist for presentation software gives you the specific questions to ask.

For organisations under formal data protection obligations, the UK ICO's guidance on UK GDPR and the NCSC's board toolkit are useful reference points when framing this as a governance question rather than a purely technical one.

A practical checklist before your next board meeting

  1. Confirm the presentation tool never uploads slide content, and get that in writing if it matters to your governance process.
  2. Restrict who receives the room link, and avoid posting it anywhere more widely accessible than a calendar invite to named attendees.
  3. Use passkeys or SSO for anyone with standing access to schedule or host sensitive sessions.
  4. Confirm the host can see and remove participants mid-session, and brief whoever is hosting on how to do it.
  5. Review your network setup in advance if the meeting happens on an unfamiliar network; see why corporate firewalls block presentation tools if you expect connectivity issues at a client or partner site.

Is WebRTC secure?

The full explanation of how WebRTC encrypts a session end to end.

Data flow diagram

The full data flow diagram behind the table above.

Presentation software security checklist

The wider checklist to run before approving any presentation tool.

Single sign-on for AV teams

Centralising who can even schedule or host a sensitive session.

FAQ

Get started

Before your next sensitive meeting, review the data flow diagram with whoever owns your governance process, or contact us if your board or legal team needs answers in writing. See the full security overview for everything self-service on the Enterprise plan.

confidentialityboard meetingsdata protectionsecurity

Written by the Cliqer Team

We build Cliqer, the internet presentation clicker used on stages, in classrooms and in boardrooms around the world.

Run your next show with Cliqer

Any slides, any phone, anywhere. The desktop app hosts the room, presenters just open a link.

Keep reading

More security & it for your next show

An IT manager and an event producer reviewing a procurement form together at a desk
Security & IT

Getting AV Software Approved by IT: A Practical Guide

What an IT security review of AV software actually checks, and how to prepare so your tool gets approved first time.
A person unlocking a laptop with a fingerprint sensor instead of typing a password
Security & IT

Passkeys Explained: Passwordless Sign-In for Busy Teams

Passkeys explained simply: how passwordless sign-in works, why it resists phishing and how to turn it on for your team.
An abstract diagram of two devices connecting through a relay server node, representing a TURN relay path
Security & IT

TURN Servers Explained: How Video Gets Through Restrictive Networks

TURN servers explained in plain language: how they relay encrypted video and control through firewalls that block you.
Newsletter

Get the next guide before your next show

Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.