Security Checklist for Presentation and Event Software

A security checklist for presentation and event software: encryption, data storage, access control and network setup.

Cliqer Team

29 August 2026 · 6 min read

An IT security reviewer checking a laptop screen showing an abstract network diagram before a live event

Somewhere between booking the venue and rehearsing the deck, someone in your organisation asks the question that stops the project cold: "what happens to our data when we use this?" If you run events, training or investor calls for a living, presentation software security is not a box to tick after the fact. It is the thing that decides whether your tool ever gets approved.

This checklist is written for the people who actually answer that question: AV managers, IT admins and event producers who need a straight answer before they can say yes to a new tool. We will walk through what to check, why it matters and how Cliqer answers each point, so you can either use it directly or take the framework to whatever you are evaluating.

Key takeaways
  • Check encryption, content storage, authentication, team roles, client integrity and network requirements before you sign off on any tool.
  • The biggest architectural win is not uploading slides at all, so a breach has nothing to expose.
  • Passkeys and role-based access control gate use once someone is already signed in.

What "presentation software" actually touches

Before you can secure something, you need to know what it does. A presenter remote or slide-control tool typically touches three things: the connection between devices, the content on the presenter's screen, and the identity of whoever is signing in.

The mistake most reviewers make is assuming all three are handled the same way. They usually are not. A tool might encrypt its login page perfectly while uploading your entire slide deck to a server you never agreed to. Ask for a data flow diagram before you ask for a demo.

Ask any vendor for a written answer to "does our presentation content ever leave our devices?" A vague answer is itself an answer.

The checklist

Here is the shortlist we give procurement teams. Treat it as a minimum bar, not the whole review.

CheckWhy it mattersWhat good looks like
Encryption in transitStops eavesdropping on public or venue Wi-FiTLS 1.2+ on every connection, no unencrypted fallback
Content storageDetermines your exposure if the vendor is breachedSlides and media never uploaded; control signals only
AuthenticationControls who can even reach the accountPasskeys or SSO, not just a shared password
Team rolesLimits blast radius of a compromised accountGranular permissions, not one shared admin login
Client software integrityConfirms the app itself has not been tampered withCode-signed installers, no silent update channels
Network requirementsDecides whether IT has to open firewall rulesOutbound-only connections, standard ports

Content that never leaves the room

The single biggest security win in presentation software is architectural, not procedural: don't upload the slides at all. Cliqer's desktop app drives PowerPoint, Keynote, Google Slides and other presentation software directly on the host's own computer. Presenters and viewers connect over encrypted WebRTC, so slide-advance commands, pointer positions and any screen or camera stream travel peer to peer, or through an encrypted relay on locked-down networks. The content itself is never stored on a Cliqer server.

That matters for board decks, product roadmaps and anything under an NDA. If you want the deeper version of this argument, we cover it in presenting confidential content.

Authentication and access control

Encryption protects the pipe. Authentication protects who gets to use it. For a team account this means two separate questions: how does an individual sign in, and what can they do once they are in.

On sign-in, look for passkey support (biometric or device-based, phishing-resistant by design) alongside or instead of passwords. We wrote a full explainer on how passkeys work if you want the mechanics.

On permissions, look for role-based access rather than one shared login. Cliqer's team roles give every member owner, admin or member permissions by default, plus custom roles that grant exactly the combination you need, such as managing API keys without managing billing. Every permission check runs server-side, so a role's limits apply to API calls too, not just what a dashboard button happens to hide. For teams on an identity provider, single sign-on lets you enforce that policy centrally rather than trusting individual passwords.

Network and firewall considerations

Event software has a habit of getting blocked the one time it matters most: on the venue's guest Wi-Fi or behind a corporate proxy. A security review should cover this before show day, not during it.

Ask whether the tool needs inbound port forwarding (it should not), which outbound ports and hosts it needs, and what happens when UDP is blocked. A tool that only works when the venue opens custom firewall rules will let you down at the one event where IT cannot make an exception in time. We cover the mechanics in why corporate firewalls block presentation tools and how TURN servers get video through restrictive networks.

How to run this checklist with Cliqer

If you are evaluating Cliqer specifically, here is where to find the answers without waiting on a sales call:

  1. Read the solution blueprint for the architecture overview: what runs where, and what data moves between them.
  2. Read the data flow diagram for the encryption and storage detail behind every connection.
  3. If you are on an Enterprise evaluation, set up SSO and SCIM provisioning from Dashboard → Team → Security, both self-service.
  4. Configure team roles so nobody has more access than their job needs.
  5. If procurement needs it in writing, contact us and we will answer point by point, including under NDA where needed.

Every one of those pages exists because a security reviewer asked for it first. If your review turns up a gap, getting AV software approved by IT covers the wider approval process around the technical checklist.

Is WebRTC secure?

How peer-to-peer connections keep presentation content off any server.

Single sign-on for AV teams

Enforcing identity policy centrally instead of trusting individual passwords.

Solution blueprint

The architecture overview reviewers ask for first: what runs where.

Getting AV software approved by IT

The wider approval process once the technical checklist is done.

FAQ

Get started

Run this checklist against whatever you are currently using, then try Cliqer free on your own computer. Free covers a single device with no card required, and you can compare every plan, including Enterprise security features, on the pricing page.

securitypresentation softwareITevent technology

Written by the Cliqer Team

We build Cliqer, the internet presentation clicker used on stages, in classrooms and in boardrooms around the world.

Run your next show with Cliqer

Any slides, any phone, anywhere. The desktop app hosts the room, presenters just open a link.

Keep reading

More security & it for your next show

An IT manager and an event producer reviewing a procurement form together at a desk
Security & IT

Getting AV Software Approved by IT: A Practical Guide

What an IT security review of AV software actually checks, and how to prepare so your tool gets approved first time.
A boardroom table with a laptop showing an abstract blurred chart, empty chairs waiting for a meeting to begin
Security & IT

Presenting Confidential Content: Data Protection for Board Meetings

Keep board presentations confidential: what should never leave your device and how to check where a tool sends data.
A person unlocking a laptop with a fingerprint sensor instead of typing a password
Security & IT

Passkeys Explained: Passwordless Sign-In for Busy Teams

Passkeys explained simply: how passwordless sign-in works, why it resists phishing and how to turn it on for your team.
Newsletter

Get the next guide before your next show

Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.