Trust & security
What a Slack workspace admin needs to know before approving the install.
This page covers every question in a typical vendor security review: OAuth scopes, data categories, AI processing policy, subprocessors, certifications, incident response, and a copyable admin packet.
Why I built this
I brought fintech-level data discipline to Slash Social.
I spent 20+ years in B2B fintech, where a data-handling mistake can end a client relationship or trigger a compliance review. I hold Slash Social to that same standard, from account permission scopes to data retention.
The idea came from a specific gap: teams that run everything else inside Slack still have to leave it to manage social media, and each switch costs context. Slash Social keeps planning, approvals, publishing, and reporting inside Slack instead.
OAuth scopes
What the app can access.
These are the Slack permissions requested during install. Scopes are read directly from the live app manifest so this table stays current with each deployment.
lists:readlists:writecommandschat:writechat:write.customizechat:write.publicusers:readchannels:readchannels:joinchannels:managechannels:historygroups:readgroups:historyim:historyim:readim:writempim:readmpim:writereactions:readfiles:readfiles:writelinks:readlinks:writelinks.embed:writereactions:writecanvases:readcanvases:writebookmarks:readbookmarks:writeconversations.connect:readconversations.connect:writeconversations.connect:manageBoundaries
What the app cannot access.
Slack's permission model restricts the app to exactly what was requested. These things are outside the app's reach regardless of any scope.
- Private channels the app has not been invited to
- Direct messages between users that do not involve the Slash Social bot
- Workspace billing, subscription, or payment data in Slack
- Other installed apps or their data
- Message history in channels where the app is not a member
- User email addresses, phone numbers, or extended profile fields not required by the workflow
- Slack admin logs outside Slash Social
- Files or attachments in conversations the app cannot access
Data
What is stored and why.
Only what is needed to operate the workflow. No customer data is sold or used for advertising.
Retention
Retention and deletion.
Uninstalling Slack disconnects the integration and invalidates the workspace access path. It does not automatically erase workspace, brand, content, billing, audit, or backup records. Disconnect or revocation invalidates connected social-account access and prevents further use of the revoked token; eligible derived data follows the deletion procedure.
An authorized owner can request a scoped export or deletion through the support form. Support verifies authority, records a correlation/reference ID, and deletes, anonymizes, or de-identifies eligible data after verification and any applicable cooldown. Use theprivacy and deletion request path with the workspace, brand, data category, and whether an export is needed first.
Security, fraud-prevention, billing, tax, legal, audit, logs, and backups may persist for a limited period when required by the retention policy or recovery process. Backups are recovery copies, not a customer-facing archive. A restore is isolated and reconciled before any production effect; restored schedules or publish work must not execute accidentally against production providers.
Read full privacy policy →AI processing
What AI does — and does not do — in Slash Social.
AI assistance is opt-in at the point of use. No AI feature publishes, approves, or takes action without explicit user intent.
Used for
- Drafting and caption suggestions
- Summaries and recommendations
- Inbox classification and sentiment/insight assistance
- Moderation/safety checks
- Transcription, vision analysis, and embeddings when a user provides or selects the input
Not used for
- Autonomous publishing
- Approval decisions
- Protected-trait profiling
- Cross-customer benchmarking or global learning datasets
- Training large language models on Slack or customer content
Slash Social does not use Slack or customer content to train large language models or cross-customer AI systems.
AI providers: OpenAI (current active AI recipient). See subprocessors below.
Subprocessors
Third-party services that process data on our behalf.
Each active subprocessor is used only to the extent required for the service it provides. Customer-directed platforms and independent controllers are classified separately on the canonical recipient schedule. Their privacy and security pages are linked for independent review.
Independent assurance
Current review status.
These entries separate available documents and completed reviews from work that has not been completed.
SOC 2 Type II
No report availableSlash Social has not completed a SOC 2 audit and cannot provide a SOC 2 report. Review the current technical and operational controls on this page or send specific questions through the security review form.
Ask a security question →Data Processing Agreement (DPA)
Published · PortalSix-approved for releaseData Processing Addendum version 1.0.0 and its processing, security, and transfer schedules are available online and approved by PortalSix for release. An execution copy tied to this exact version and SHA-256 is available on request.
Read the DPA →Slack Marketplace review
Not publicly listedSlash Social is not yet available through a public Slack Marketplace listing. Direct installation availability depends on the current access mode and workspace admin review.
GDPR / CCPA
Covered by privacy policyUser rights under GDPR and CCPA are described in the privacy policy. Authorized users can request access, correction, export, or deletion. The current DPA is published online and approved by PortalSix for release.
Read privacy policy →Incident response
How we respond to security incidents.
Security and incident reports use security@slashsocial.app or the security form. The incident runbook uses role-based Incident Commander, Security Lead, Communications Owner, Scribe, and Service Owner responsibilities; it does not promise 24/7 coverage or a contractual response SLA.
- Sev 0: confirmed security/privacy or uncontrolled spend/publish risk
- Sev 1: duplicate/incorrect publication, data loss, cross-tenant exposure, broad outage, or payment correctness
- Sev 2: blocked core workflow with safe data
- Sev 3: degraded optional feature, question, or feature request
Security and incident reports use security@slashsocial.app or the security form. The incident runbook uses role-based Incident Commander, Security Lead, Communications Owner, Scribe, and Service Owner responsibilities; it does not promise 24/7 coverage or a contractual response SLA.
Security contact
Questions for a security review.
Send security review questions, vulnerability reports, and requests for control details through the security review form. Use the general support form for billing, setup, account, and routine privacy requests.
Do not include passwords, access tokens, or unnecessary customer content.
Admin packet
Copy this for your IT or security review form.
Pre-formatted summary of all the information on this page. Copy the text block below and paste it into your vendor review tool, Jira ticket, or security questionnaire.
Ready when your team is
Add Slash Social when your workspace owner is ready.
Start from Slack, choose the first brand, and build the workflow your team wants to use first.