Slack security review: SOC 2, AI training & subprocessors

What Slack publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
85/100
SOC 2
SOC 2
ISO 27001
Claimed
Trains AI on your data?
See quotes
Subprocessors
Not found

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Slack train AI on your data?

Statements differ between pages

Slack's own words (slack.com/trust/ai-principles):

Your Customer Data (like messages and files) is never used to train any LLMs.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
We build and train models so that they cannot reproduce Customer Data, and the outputs of the models cannot be linked to data from a specific customer.
slack.com/trust/ai-principles
Our approach to AI is grounded in these three principles: Your data is never used to train large language models.
slack.com/trust/ai-principles

Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.

Certifications Slack claims

Certification or reportMentioned on
SOC 2slack.com/trust/compliance
SOC 3slack.com/trust/compliance
ISO/IEC 27001slack.com/trust/compliance
ISO/IEC 27017slack.com/trust/compliance
ISO/IEC 27018slack.com/trust/compliance
ISO/IEC 27701slack.com/trust/compliance
ISO/IEC 42001slack.com/trust/compliance
HIPAAslack.com/trust/compliance
FedRAMPslack.com/trust
TISAXslack.com/trust/compliance
IRAPslack.com/trust/compliance
C5slack.com/trust/compliance

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Slack for the SOC 2 report or ISO certificate.

Slack subprocessors

Our reader didn't find a subprocessor list on Slack's public pages. It may be published somewhere we couldn't reach, such as a trust portal that needs JavaScript or a login. Ask Slack for it if you need it.

Security features mentioned

SSO / SAMLNot found
SCIM provisioningNot found
Multi-factor authenticationNot found
Encryption at restNot found
Encryption in transitNot found
Penetration testingNot found
Bug bounty / disclosure programNot found
Audit logsNot found
Data residencyMentioned United States, US, United Kingdom, Canada, Ireland, India, France
security.txt contacthttps://hackerone.com/slack/

Key documents

Trust / security centerslack.com/trust
Privacy policyslack.com/trust/privacy/privacy-policy
Subprocessor listNot found
Data processing agreement (DPA)slack.com/terms-of-service/data-processing
AI policyslack.com/trust/ai-principles
TermsNot found
Status pageslack-status.com

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15No
DPA available10Yes
AI training policy stated15Yes
security.txt contact5Yes
Status page10Yes

The score measures how much of a standard security review our reader could answer from Slack's public pages. It is not a rating of how secure Slack is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Communication vendors

Aircall · Braze · Customer.io · Dialpad · Discord · Front · Gong · Klaviyo · Mailchimp · Postmark · RingCentral · SendGrid

Source: Slack's own public website (6 pages read on October 10, 2026). Stormap is not affiliated with Slack. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.