Trust & security

What a Slack workspace admin needs to know before approving the install.

This page covers every question in a typical vendor security review: OAuth scopes, data categories, AI processing policy, subprocessors, certifications, incident response, and a copyable admin packet.

Why I built this

I brought fintech-level data discipline to Slash Social.

I spent 20+ years in B2B fintech, where a data-handling mistake can end a client relationship or trigger a compliance review. I hold Slash Social to that same standard, from account permission scopes to data retention.

The idea came from a specific gap: teams that run everything else inside Slack still have to leave it to manage social media, and each switch costs context. Slash Social keeps planning, approvals, publishing, and reporting inside Slack instead.

OAuth scopes

What the app can access.

These are the Slack permissions requested during install. Scopes are read directly from the live app manifest so this table stays current with each deployment.

lists:read
Read Slack Lists used for pipeline, approval, and idea records.The app reads configured list records to render and reconcile content work in Slack. Reads only lists connected to the installed workspace workflow; list records are stored as tenant-scoped product mappings when needed.
lists:write
Create and update Slack Lists records.The app writes pipeline, approval, and idea state when a workspace enables those Slack-native surfaces. Writes only records for the installed workspace and configured brand workflows; it does not write unrelated workspace lists.
commands
Receive and respond to Slash Social slash commands.Commands such as /social, /social-create, and /social-approve start or open product workflows. Command payloads are processed to identify the requested workflow and tenant context; they are not used for advertising or model training.
chat:write
Post workflow messages and notifications.The app sends approval cards, publishing status, recovery guidance, and command responses to configured Slack destinations. Messages contain workflow status and customer-selected content for the requesting workspace, brand, and authorized recipients.
chat:write.customize
Customize the bot identity for supported workflow messages.The app uses the configured Slash Social presentation when a workflow requires a custom message name or icon. Only message presentation metadata and the workflow message are sent; it does not grant access to unrelated messages.
chat:write.public
Post to eligible public channels when a configured workflow requires it.The app can deliver a configured approval or notification to a public channel without first joining it where Slack permits. Writes only the requested workflow message and does not read the channel merely because it can post there.
users:read
Read workspace member identities for routing and reviewer selection.Member names and IDs populate assignee, approver, creator, and role selectors. Uses workspace member identity metadata for authorization and routing; it does not request email addresses, phone numbers, or extended profiles.
channels:read
Read public channel metadata.Channel pickers and configured routing resolve eligible channels for approvals, inbox work, and knowledge workflows. Reads channel metadata for the installed workspace; message content is read only in a configured workflow and accessible conversation.
channels:join
Join eligible public channels when a workflow requires app membership.Setup and reconciliation can join a configured public approval, inbox, or delivery channel. Joining does not authorize access to private channels or unrelated conversations; the joined channel remains workspace-admin controlled.
channels:manage
Create and configure channels for approved workflows.The app can create or configure an approval or client-feedback channel when the workspace explicitly enables that workflow. Channel creation and membership changes are limited to the requested workspace workflow and recorded for tenant/audit context.
channels:history
Read history in accessible public channels when a user requests context ingestion.Brief, idea, approval, and knowledge workflows can use selected channel/thread context. Reads only channels the app can access and the configured workflow selects; content remains scoped to the requesting organization and brand.
groups:read
Read metadata for private channels the app can access.Private approval and routing channels can be selected and resolved after the app is invited. The app cannot read private channels it has not been invited to; accessible metadata is tenant-scoped.
groups:history
Read history in accessible private channels when a configured workflow requests it.Private-channel briefs, threads, approvals, and selected knowledge context can be ingested. Only invited private channels and user/workspace-selected context are processed; unrelated private-channel history is not crawled.
im:history
Receive bot direct-message history for explicit DM intake.A user can DM the Slash Social bot a URL, file, or text to start a draft or intake workflow. Processes messages sent to the bot, not private DMs between users; selected intake may become a tenant-scoped draft or media record.
im:read
Read bot-DM conversation metadata.The app resolves the bot DM needed for intake, notifications, and recovery prompts. Access is limited to conversations involving the app and the installed workspace; it does not expose user-to-user DMs.
im:write
Open or send bot direct messages.The app sends approval notifications, publishing failure alerts, and recovery prompts to affected users. Only requested workflow notifications and user-selected content are sent to authorized recipients.
mpim:read
Read group-DM metadata where a configured notification workflow uses it.The app resolves a multi-party conversation when a team chooses group notification context. Processes only the group-DM context involving the app and the requested workflow; it does not crawl arbitrary group DMs.
mpim:write
Open or send group-DM workflow messages.The app can deliver a shared approval or recovery notification to a configured group DM. Writes only the requested workflow message to authorized recipients in the installed workspace.
reactions:read
Read reactions used as configured workflow signals.Reaction-based idea capture and acknowledgement flows inspect reactions on accessible messages. Reads reaction metadata only where the configured workflow has access; it is not used for cross-customer profiling.
files:read
Read files explicitly shared for intake or a selected accessible workflow.Users can share media, documents, or audio for post creation, Canvas/knowledge intake, transcription, or review. Files are processed only when shared/selected for the workflow and may be stored as product artifacts under tenant scope; files outside accessible conversations are not read.
files:write
Upload workflow outputs and rendered previews to Slack.The app shares report exports, analytics files, and preview assets through Slack's supported external upload flow. Uploads contain the requested report or preview and are delivered to the configured workspace destination; the app does not upload unrelated files.
links:read
Receive link-shared events for configured link workflows.A shared content-item or social URL can trigger intake or an eligible preview. Processes URLs and related event metadata for the requesting workflow; it does not crawl arbitrary links or Slack history.
links:write
Configure Slack link unfurl behavior.The app registers or updates eligible previews for Slash Social content links. Writes only the configured preview behavior and link presentation for product content.
links.embed:write
Create custom unfurls for eligible Slash Social content links.Users can see a content-item preview when a supported Slash Social link is shared. The unfurl contains product workflow metadata and selected content; it does not grant access to unrelated URLs.
reactions:write
Add a reaction acknowledgement where a workflow uses it.Asset or intake flows can acknowledge a successfully captured message with a reaction. Writes only the configured acknowledgement reaction to the requested accessible message.
canvases:read
Read selected Slack Canvas content for configured knowledge or content workflows.A user can select a Canvas containing brand context, guidelines, or a brief for ingestion. Processes only selected/accessibly shared Canvas content and stores derived product context under tenant and brand scope.
canvases:write
Create or update Slack Canvases for configured workflow artifacts.The knowledge-base workflow can store or update brand context, guidelines, or briefs in a configured Canvas. Writes only the requested workflow artifact in the installed workspace; it does not edit unrelated Canvases.
bookmarks:read
Read channel bookmark metadata used to detect existing workflow links.List provisioning checks whether a relevant Slack List or workflow link is already surfaced in a configured channel. Reads bookmark metadata for the configured channel and does not read unrelated bookmark destinations.
bookmarks:write
Add workflow links to configured channel bookmarks.The app can surface a provisioned Slack List or workflow link in a configured channel header/bookmark area. Writes only the requested Slash Social workflow link to the configured channel.
conversations.connect:read
Read Slack Connect invite and shared-channel state.Client approval reconciliation checks whether an external reviewer invite or shared channel is pending, accepted, declined, or changed. Uses shared-channel state only for configured client approval workflows and keeps client/workspace records tenant-scoped.
conversations.connect:write
Send Slack Connect invites for client approval.A workspace can invite an external client reviewer to the configured approval channel. Sends only the requested invite and channel context; it does not grant the external reviewer access to internal workspace data.
conversations.connect:manage
Manage the lifecycle of Slack Connect approval invitations.The app can reconcile, update, or close the invite lifecycle for a configured client approval channel. Changes are limited to the configured shared-channel workflow and recorded with workspace/client authorization context.

Boundaries

What the app cannot access.

Slack's permission model restricts the app to exactly what was requested. These things are outside the app's reach regardless of any scope.

  • Private channels the app has not been invited to
  • Direct messages between users that do not involve the Slash Social bot
  • Workspace billing, subscription, or payment data in Slack
  • Other installed apps or their data
  • Message history in channels where the app is not a member
  • User email addresses, phone numbers, or extended profile fields not required by the workflow
  • Slack admin logs outside Slash Social
  • Files or attachments in conversations the app cannot access

Data

What is stored and why.

Only what is needed to operate the workflow. No customer data is sold or used for advertising.

Slack and workspace identityInstall, authorize, route, audit, and notify the correct workspace/user/channel. Tenant-scoped product records; runtime secrets remain server-side and are encrypted before database storage.
Selected Slack messages, links, files, Canvases, Lists, and shared-channel stateRun the user- or workspace-configured intake, planning, approval, knowledge, reporting, and client-review workflow. D1/R2/queues as needed for the requested workflow, with org/brand/access scoping.
Social account references, tokens, posts, and provider statusConnect certified accounts, schedule/publish, reconcile provider outcomes, and recover failures. Server-side product records; connected-account tokens are encrypted and invalidated on disconnect/revocation.
Drafts, media, approvals, schedules, reports, inbox records, and audit historyProvide the canonical Create → Approvals → Calendar → Publish/Recover workflow and its evidence. Tenant- and brand-scoped product records and artifacts.
Billing and usage stateApply plan entitlements, limits, checkout state, invoices, cancellation, and reconciliation. Org-scoped local billing projection plus Stripe provider records; card details and payment secrets are not stored in Slack artifacts.
AI inference context and outputsProvide requested drafting, summarization, classification, moderation, transcription, vision, embedding, and insight assistance. Submitted context is sent through the AI broker for inference; outputs or derived artifacts are stored only when required by the product workflow.

Retention

Retention and deletion.

Uninstalling Slack disconnects the integration and invalidates the workspace access path. It does not automatically erase workspace, brand, content, billing, audit, or backup records. Disconnect or revocation invalidates connected social-account access and prevents further use of the revoked token; eligible derived data follows the deletion procedure.

An authorized owner can request a scoped export or deletion through the support form. Support verifies authority, records a correlation/reference ID, and deletes, anonymizes, or de-identifies eligible data after verification and any applicable cooldown. Use theprivacy and deletion request path with the workspace, brand, data category, and whether an export is needed first.

Security, fraud-prevention, billing, tax, legal, audit, logs, and backups may persist for a limited period when required by the retention policy or recovery process. Backups are recovery copies, not a customer-facing archive. A restore is isolated and reconciled before any production effect; restored schedules or publish work must not execute accidentally against production providers.

Read full privacy policy →

AI processing

What AI does — and does not do — in Slash Social.

AI assistance is opt-in at the point of use. No AI feature publishes, approves, or takes action without explicit user intent.

Used for

  • Drafting and caption suggestions
  • Summaries and recommendations
  • Inbox classification and sentiment/insight assistance
  • Moderation/safety checks
  • Transcription, vision analysis, and embeddings when a user provides or selects the input

Not used for

  • Autonomous publishing
  • Approval decisions
  • Protected-trait profiling
  • Cross-customer benchmarking or global learning datasets
  • Training large language models on Slack or customer content

Slash Social does not use Slack or customer content to train large language models or cross-customer AI systems.

AI providers: OpenAI (current active AI recipient). See subprocessors below.

Subprocessors

Third-party services that process data on our behalf.

Each active subprocessor is used only to the extent required for the service it provides. Customer-directed platforms and independent controllers are classified separately on the canonical recipient schedule. Their privacy and security pages are linked for independent review.

Cloudflare, Inc.
Application hosting, edge delivery, security, databases, object storage, key-value storage, queues, and durable state.Global infrastructure; no regional data-residency commitment
HubSpot, Inc.
Website contact, support, security-review, privacy-request, and DPA-request form intake and communication mirroring.United States and other locations described by HubSpot
OpenAI OpCo, LLC
User-requested AI drafting, classification, summarization, transcription, image generation, and related model operations.United States and other locations described by OpenAI

Independent assurance

Current review status.

These entries separate available documents and completed reviews from work that has not been completed.

SOC 2 Type II

No report available

Slash Social has not completed a SOC 2 audit and cannot provide a SOC 2 report. Review the current technical and operational controls on this page or send specific questions through the security review form.

Ask a security question →

Data Processing Agreement (DPA)

Published · PortalSix-approved for release

Data Processing Addendum version 1.0.0 and its processing, security, and transfer schedules are available online and approved by PortalSix for release. An execution copy tied to this exact version and SHA-256 is available on request.

Read the DPA →

Slack Marketplace review

Not publicly listed

Slash Social is not yet available through a public Slack Marketplace listing. Direct installation availability depends on the current access mode and workspace admin review.

GDPR / CCPA

Covered by privacy policy

User rights under GDPR and CCPA are described in the privacy policy. Authorized users can request access, correction, export, or deletion. The current DPA is published online and approved by PortalSix for release.

Read privacy policy →

Incident response

How we respond to security incidents.

Security and incident reports use [email protected] or the security form. The incident runbook uses role-based Incident Commander, Security Lead, Communications Owner, Scribe, and Service Owner responsibilities; it does not promise 24/7 coverage or a contractual response SLA.

  • Sev 0: confirmed security/privacy or uncontrolled spend/publish risk
  • Sev 1: duplicate/incorrect publication, data loss, cross-tenant exposure, broad outage, or payment correctness
  • Sev 2: blocked core workflow with safe data
  • Sev 3: degraded optional feature, question, or feature request

Security and incident reports use [email protected] or the security form. The incident runbook uses role-based Incident Commander, Security Lead, Communications Owner, Scribe, and Service Owner responsibilities; it does not promise 24/7 coverage or a contractual response SLA.

Security contact

Questions for a security review.

Send security review questions, vulnerability reports, and requests for control details through the security review form. Use the general support form for billing, setup, account, and routine privacy requests.

Do not include passwords, access tokens, or unnecessary customer content.

Admin packet

Copy this for your IT or security review form.

Pre-formatted summary of all the information on this page. Copy the text block below and paste it into your vendor review tool, Jira ticket, or security questionnaire.

Ready when your team is

Add Slash Social when your workspace owner is ready.

Start from Slack, choose the first brand, and build the workflow your team wants to use first.

Public site guide

Ask Slash Social

Answers come from Slash Social’s public site.

Ask about product fit, features, platforms, pricing, or how Slash Social works.

Use public questions only. Don’t share workspace content, credentials, or personal data.