Skip to main content
Skip to main content

Slack Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Slack before Slack sends a questionnaire or a security document.

Slack's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Slack — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Slack's own trust page.

FedRAMP Certified — Class C (Moderate) Checked August 2026.

Slack is FedRAMP Certified at Class C (Moderate) via the Agency path (package FR1823447014). The certified offering is Slack's government cloud; commercial Slack workspaces are not covered.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
26 of 27 sources returned data
Questionnaire
112 / 133 answered
84% from public evidence
Last assessed
Aug 28, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 33.9 years🟢Infrastructure: 2 open ports, 0 CVEs
FedRAMP Status
Slack is listed on the FedRAMP Marketplace — Independently verified (checked August 2026).
SOC 2 Status
Slack — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Slack returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Slack a Moderate Risk tier across 27 intelligence sources, 26 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 26 returning usable evidence. The Slack assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Slack Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

112 questions answered before Slack responds.

ThirdProof used public evidence to pre-fill 84% of a 133-question vendor security questionnaire — without waiting for Slack. The remaining 21 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

Slack is PCI Level 4 Merchant and has completed PCI DSS SAQ-A, using a third party to process credit card information securely.

Public evidencehigh confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

Slack offers a Data Processing Addendum (DPA) with standard contractual clauses available to all customers regardless of plan.

Public evidencehigh confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

HIPAA compliance / BAA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Encryption at rest claim found on trust page (Vendor attested)

Public evidencemedium confidence

+ 107 additional evidence-backed answers

Get the Complete Slack Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Slack sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • FedRAMP — independently verified
  • FedRAMP Authorization Independently Verified
  • FedRAMP Authorization Confirmed via Registry
  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Vendor Commits to Not Training on Customer Data

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Governance & Risk — 4 of 10 questions need vendor input
  • Data Security — 4 of 14 questions need vendor input
  • Access Control — 3 of 12 questions need vendor input
  • Incident Response — 2 of 10 questions need vendor input

Reviewing Slack for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Slack

Slack is a mature enterprise communication and collaboration platform with a Tier 3 (Moderate Risk) rating reflecting a balanced risk profile common among large SaaS vendors.

Area Requiring Attention

Positive signals include FedRAMP Moderate authorization verified through the FedRAMP Marketplace, a clear commitment to not training customer data on AI models, established incident response procedures tested annually, and a strong infrastructure footprint with only 2 open ports (80, 443) and no known CVEs. The vendor maintains comprehensive access controls including multi-factor authentication, privileged access logging for at least two years, and quarterly access reviews.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence was independently sourced from external data repositories, public registries, threat intelligence feeds, and archived media without vendor participation or input.

Investigation Findings

4 findings identified for Slack

1 medium3 low
medium

Extended data retention for AI processing

Slack retains customer data for AI processing (specifically for Slack AI recap features) for 90 days. This exceeds the widely-adopted 30-day industry standard for ephemeral processing, extending the window during which customer data is retained in AI processing infrastructure.

low

Customer environment compromise reported on the vendor's platform

A November 2025 incident reported by CSO Online documented a breach at Nikkei, a Slack customer, where 17,000+ users' sensitive data was leaked via Slack. This is a shared-responsibility incident — the breach occurred in the customer's environment (Nikkei's Slack workspace), not in Slack's infrastructure or platform controls. …

low

Security incident reported involving the vendor (historical)

In January 2023, Cybersecurity Dive reported that Slack employee tokens were stolen and a GitHub repository containing internal code was breached. This was a vendor-side incident affecting Slack's own infrastructure and development environment, not customer data. …

low

No subprocessor page found

No publicly accessible subprocessor or third-party vendor page was discovered for Slack. The vendor's security practices page identifies AWS as an infrastructure provider, but does not publish a comprehensive, machine-readable subprocessor list. …

Showing the 4 most severe of 5 findings.

Security Strengths

Evidence that positively supports Slack's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

FedRAMP Authorization Independently Verified

Trust & Compliance Page Scan

FedRAMP Authorization Confirmed via Registry

Certification Registry Verification

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Vendor Commits to Not Training on Customer Data

AI Data Usage Policy

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Slack complete vendor assessment

Tier 3
Moderate Risk
112 / 133
questionnaire answers
27
sources checked
Aug 28, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 28, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Slack Enterprise Compliance Context

Slack (now part of Salesforce) processes internal communications, file sharing, and integration data that often includes sensitive business information. Slack claims SOC 2, FedRAMP, HIPAA, GDPR, and CCPA compliance. Since the Salesforce acquisition, Slack's security program benefits from Salesforce's enterprise compliance infrastructure, but organizations should verify certification scope independently. For organizations also evaluating Salesforce products, consider assessing both vendors holistically to understand shared compliance boundaries.

Slack Security Posture

ThirdProof investigated Slack across 27 intelligence sources. Domain reputation is clean across 94 security engines with a 33-year domain history. Sanctions screening returned clear with no matches. No malware, phishing indicators, or IP reputation issues were detected. The HTTP security grade of C+ (60/100) reflects header configuration gaps that are common in complex enterprise applications but should be documented in your vendor risk register.

Frequently asked about Slack

Does Slack have SOC 2 Type II?+
Slack states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is Slack on the OFAC sanctions list?+
Slack returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Slack's vendor risk tier?+
ThirdProof assigned Slack a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Slack.
Has Slack had any data breaches or security incidents?+
ThirdProof's assessment as of August 2026 records 2 incident-related findings for Slack. The most severe concerns customer environment compromise reported on the vendor's platform. Each finding states whether the incident affected Slack's own systems, a customer's environment, or a third party — a distinction that changes what you should ask about — and links to the source it was drawn from. The complete assessment carries all of them with their evidence.
Is Slack PCI DSS compliant?+
Slack is PCI Level 4 Merchant and has completed PCI DSS SAQ-A, using a third party to process credit card information securely. ThirdProof records this from Slack's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does Slack support HIPAA and sign BAAs?+
HIPAA compliance / BAA claim found on trust page (Vendor attested) If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Slack security questionnaire?+
Yes. ThirdProof answered 112 of 133 questions (84%) about Slack from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 21 are listed as open, so the follow-up you send Slack is short and specific.
What evidence should I request from Slack?+
Public evidence settles a large part of the review, so the request you send should be short. Ask Slack for the current SOC 2 report and, where applicable, a bridge letter covering the period since the report date; the audit scope — which systems and services the report actually covers; written answers on governance & risk, data security, access control; contractual commitments, cyber insurance, and the current subprocessor list. Everything ThirdProof could already establish is recorded with its source, so you are not asking Slack to re-confirm what is already documented.

If Slack is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Slack assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required