Assessed before company and product grades were shown separately; see the product assessments below.
Products assessed
A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.
Certifications
What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.
Scope covers the ISMS supporting Slack Technologies, LLC and its Team Collaboration Platform. It does NOT name Slack AI specifically, so this is platform-level coverage rather than product-scoped. Certified by Schellman Compliance, LLC; original registration 10 Nov 2017, issue date 8 Jan 2026.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 27001:2022 certificate of registration published by Slack (Schellman Compliance, LLC, version 11) · checked Sep 1, 2026
Valid until Nov 9, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Stated on the GDPR commitment page alongside SOC 3. No report or scope statement was available.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
The certificate's scope names Slack AI explicitly, so the AI management system certification covers the assessed product rather than only its parent. Issued by MSECB, certificate CERT-001117, certified since 2025-09-30.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 42001:2023 certificate published by Salesforce/Slack (MSECB, certificate CERT-001117) · checked Sep 1, 2026
Valid until Sep 29, 2028
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Sep 1, 2026
27701 is carried as an extension of the same ISO/IEC 27001 certificate, in the role of a personally identifiable information processor. Platform-level, not scoped to Slack AI.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 27701:2019 extension recorded on Slack's ISO/IEC 27001:2022 certificate (Schellman Compliance, LLC) · checked Sep 1, 2026
Valid until Nov 9, 2026
Australian instance of the Slack Cloud platform, assessed at PROTECTED against the ISM (December 2025) under the ACSC framework Phase 1a. An IRAP assessment is not an authorisation - the letter states cloud consumers remain responsible for granting an Authority to Operate in their own environment.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · IRAP Letter of Assessment published by Slack (CyberCX, 26 May 2026) · checked Sep 1, 2026
How to read this
This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Sep 1, 2026.
