
Somewhere between booking the venue and rehearsing the deck, someone in your organisation asks the question that stops the project cold: "what happens to our data when we use this?" If you run events, training or investor calls for a living, presentation software security is not a box to tick after the fact. It is the thing that decides whether your tool ever gets approved.
This checklist is written for the people who actually answer that question: AV managers, IT admins and event producers who need a straight answer before they can say yes to a new tool. We will walk through what to check, why it matters and how Cliqer answers each point, so you can either use it directly or take the framework to whatever you are evaluating.
- Check encryption, content storage, authentication, team roles, client integrity and network requirements before you sign off on any tool.
- The biggest architectural win is not uploading slides at all, so a breach has nothing to expose.
- Passkeys and role-based access control gate use once someone is already signed in.
What "presentation software" actually touches
Before you can secure something, you need to know what it does. A presenter remote or slide-control tool typically touches three things: the connection between devices, the content on the presenter's screen, and the identity of whoever is signing in.
The mistake most reviewers make is assuming all three are handled the same way. They usually are not. A tool might encrypt its login page perfectly while uploading your entire slide deck to a server you never agreed to. Ask for a data flow diagram before you ask for a demo.
The checklist
Here is the shortlist we give procurement teams. Treat it as a minimum bar, not the whole review.
| Check | Why it matters | What good looks like |
|---|---|---|
| Encryption in transit | Stops eavesdropping on public or venue Wi-Fi | TLS 1.2+ on every connection, no unencrypted fallback |
| Content storage | Determines your exposure if the vendor is breached | Slides and media never uploaded; control signals only |
| Authentication | Controls who can even reach the account | Passkeys or SSO, not just a shared password |
| Team roles | Limits blast radius of a compromised account | Granular permissions, not one shared admin login |
| Client software integrity | Confirms the app itself has not been tampered with | Code-signed installers, no silent update channels |
| Network requirements | Decides whether IT has to open firewall rules | Outbound-only connections, standard ports |
Content that never leaves the room
The single biggest security win in presentation software is architectural, not procedural: don't upload the slides at all. Cliqer's desktop app drives PowerPoint, Keynote, Google Slides and other presentation software directly on the host's own computer. Presenters and viewers connect over encrypted WebRTC, so slide-advance commands, pointer positions and any screen or camera stream travel peer to peer, or through an encrypted relay on locked-down networks. The content itself is never stored on a Cliqer server.
That matters for board decks, product roadmaps and anything under an NDA. If you want the deeper version of this argument, we cover it in presenting confidential content.

Authentication and access control
Encryption protects the pipe. Authentication protects who gets to use it. For a team account this means two separate questions: how does an individual sign in, and what can they do once they are in.
On sign-in, look for passkey support (biometric or device-based, phishing-resistant by design) alongside or instead of passwords. We wrote a full explainer on how passkeys work if you want the mechanics.
On permissions, look for role-based access rather than one shared login. Cliqer's team roles give every member owner, admin or member permissions by default, plus custom roles that grant exactly the combination you need, such as managing API keys without managing billing. Every permission check runs server-side, so a role's limits apply to API calls too, not just what a dashboard button happens to hide. For teams on an identity provider, single sign-on lets you enforce that policy centrally rather than trusting individual passwords.
Network and firewall considerations
Event software has a habit of getting blocked the one time it matters most: on the venue's guest Wi-Fi or behind a corporate proxy. A security review should cover this before show day, not during it.
Ask whether the tool needs inbound port forwarding (it should not), which outbound ports and hosts it needs, and what happens when UDP is blocked. A tool that only works when the venue opens custom firewall rules will let you down at the one event where IT cannot make an exception in time. We cover the mechanics in why corporate firewalls block presentation tools and how TURN servers get video through restrictive networks.

How to run this checklist with Cliqer
If you are evaluating Cliqer specifically, here is where to find the answers without waiting on a sales call:
- Read the solution blueprint for the architecture overview: what runs where, and what data moves between them.
- Read the data flow diagram for the encryption and storage detail behind every connection.
- If you are on an Enterprise evaluation, set up SSO and SCIM provisioning from Dashboard → Team → Security, both self-service.
- Configure team roles so nobody has more access than their job needs.
- If procurement needs it in writing, contact us and we will answer point by point, including under NDA where needed.
Every one of those pages exists because a security reviewer asked for it first. If your review turns up a gap, getting AV software approved by IT covers the wider approval process around the technical checklist.
FAQ
Any tool that touches your devices and network carries some risk, but the risk profile varies enormously. Tools that upload your content to a server carry more exposure than tools that keep control signals peer to peer and never touch the slides themselves. The questions in this checklist are designed to surface that difference quickly, before you have signed a contract or trained a room full of presenters on a tool you later have to replace.
A vendor who cannot produce a written data flow diagram or answer basic questions about encryption and storage. If nobody at the company can explain where your data goes, assume the worst.
No. Free, Pro and Ultra plans cover solo presenters and small teams with passkey and password sign-in. SSO, SCIM and custom team roles are Enterprise features for organisations that need centralised identity control.
No. The desktop app drives your presentation software on your own computer. Slides are never uploaded; only control signals and, if you choose to share them, encrypted video streams travel between participants.
Get started
Run this checklist against whatever you are currently using, then try Cliqer free on your own computer. Free covers a single device with no card required, and you can compare every plan, including Enterprise security features, on the pricing page.
Show Control from the Tech Table: How AV Crews Run Slides
Slide advance is often the weak link in show control. How AV crews run it from the desk instead of a laptop on the side.
Controlling Presentations Inside a vMix Production
Advance slides inside a live vMix production without a second operator, using native presentation control in vMix.
Run your next show with Cliqer
Keep reading
More security & it for your next show


Presenting Confidential Content: Data Protection for Board Meetings

Passkeys Explained: Passwordless Sign-In for Busy Teams
Get the next guide before your next show
Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.
