Compliance frameworks, security audits, and quality certifications this company maintains.
Slack holds SOC 2 Type II certification covering security, availability, and confidentiality, providing enterprise IT and procurement teams assurance that Slack's messaging infrastructure and data storage meet independent security control requirements.
Slack's information security management system is ISO 27001 certified, demonstrating systematic security practices for managing the sensitive business communications and file data of 200,000+ paying organizations on the Slack platform.
Slack is ISO 27017 certified for cloud service security controls, covering the specific risks of cloud-hosted business messaging including multi-tenant data isolation, admin access controls, and channel-level encryption for enterprise customers.
Slack complies with GDPR requirements for EU customer data, providing data processing agreements, EU data residency via Slack on AWS Europe, and data subject rights tooling for the personal communications data of EU-based workspace members.
Slack supports HIPAA-compliant deployments through a Business Associate Agreement for healthcare organizations, enabling hospitals and healthcare teams to use Slack for clinical care coordination while protecting protected health information in messages and files.
Regulatory
FedRAMP Moderate
In ProgressSlack is pursuing FedRAMP Moderate authorization to enable US federal government agencies to use Slack for mission-critical team communication, complementing Salesforce's existing FedRAMP government cloud offering.
Slack's Enterprise Grid with EKM and DLP integrations supports FINRA compliance requirements for financial services firms, enabling broker-dealers to use Slack for business communications with the required message retention, archiving, and supervision capabilities.
Slack complies with the California Consumer Privacy Act, providing California users and enterprise administrators with data access, deletion, and opt-out rights for the personal data collected through Slack workspace usage and communication metadata.
Slack publishes a SOC 3 report as a publicly available general-use security certification, allowing prospective enterprise customers to review Slack's security controls without requiring a confidential NDA-protected SOC 2 report exchange.
Slack's desktop and mobile applications conform to WCAG 2.1 AA accessibility standards, supporting screen readers, keyboard navigation, and high-contrast modes to ensure employees with disabilities can fully participate in Slack-based team communication.