Q39
Are you PCI DSS compliant? At what level?
Slack is PCI Level 4 Merchant and has completed PCI DSS SAQ-A, using a third party to process credit card information securely.
ThirdProof independently checks public intelligence sources to show what your team can verify about Slack before Slack sends a questionnaire or a security document.
Slack's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Slack — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Slack's own trust page.
✓ FedRAMP Certified — Class C (Moderate) Checked August 2026.
Slack is FedRAMP Certified at Class C (Moderate) via the Agency path (package FR1823447014). The certified offering is Slack's government cloud; commercial Slack workspaces are not covered.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The Slack assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Slack Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 84% of a 133-question vendor security questionnaire — without waiting for Slack. The remaining 21 are listed as open, so the follow-up you send is short and specific.
Q39
Slack is PCI Level 4 Merchant and has completed PCI DSS SAQ-A, using a third party to process credit card information securely.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Slack offers a Data Processing Addendum (DPA) with standard contractual clauses available to all customers regardless of plan.
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
Encryption at rest claim found on trust page (Vendor attested)
+ 107 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Slack for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Slack
Slack is a mature enterprise communication and collaboration platform with a Tier 3 (Moderate Risk) rating reflecting a balanced risk profile common among large SaaS vendors.
Positive signals include FedRAMP Moderate authorization verified through the FedRAMP Marketplace, a clear commitment to not training customer data on AI models, established incident response procedures tested annually, and a strong infrastructure footprint with only 2 open ports (80, 443) and no known CVEs. The vendor maintains comprehensive access controls including multi-factor authentication, privileged access logging for at least two years, and quarterly access reviews.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence was independently sourced from external data repositories, public registries, threat intelligence feeds, and archived media without vendor participation or input.
4 findings identified for Slack
Slack retains customer data for AI processing (specifically for Slack AI recap features) for 90 days. This exceeds the widely-adopted 30-day industry standard for ephemeral processing, extending the window during which customer data is retained in AI processing infrastructure.
A November 2025 incident reported by CSO Online documented a breach at Nikkei, a Slack customer, where 17,000+ users' sensitive data was leaked via Slack. This is a shared-responsibility incident — the breach occurred in the customer's environment (Nikkei's Slack workspace), not in Slack's infrastructure or platform controls. …
In January 2023, Cybersecurity Dive reported that Slack employee tokens were stolen and a GitHub repository containing internal code was breached. This was a vendor-side incident affecting Slack's own infrastructure and development environment, not customer data. …
No publicly accessible subprocessor or third-party vendor page was discovered for Slack. The vendor's security practices page identifies AWS as an infrastructure provider, but does not publish a comprehensive, machine-readable subprocessor list. …
Showing the 4 most severe of 5 findings.
Evidence that positively supports Slack's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Slack complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Slack (now part of Salesforce) processes internal communications, file sharing, and integration data that often includes sensitive business information. Slack claims SOC 2, FedRAMP, HIPAA, GDPR, and CCPA compliance. Since the Salesforce acquisition, Slack's security program benefits from Salesforce's enterprise compliance infrastructure, but organizations should verify certification scope independently. For organizations also evaluating Salesforce products, consider assessing both vendors holistically to understand shared compliance boundaries.
ThirdProof investigated Slack across 27 intelligence sources. Domain reputation is clean across 94 security engines with a 33-year domain history. Sanctions screening returned clear with no matches. No malware, phishing indicators, or IP reputation issues were detected. The HTTP security grade of C+ (60/100) reflects header configuration gaps that are common in complex enterprise applications but should be documented in your vendor risk register.
Represent Slack? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Slack assessment above is already written; ask for it and it lands in your inbox.