← Trust Directory

Slack

slack.com · 1 assessment

Slack
AI assurance review required
1 blocking issue to resolve before signing
Assessed Sep 1, 2026 · public evidence coverage 33% · evidence confidence medium high · methodology 0.7.0

Assessed before company and product grades were shown separately; see the product assessments below.

Products assessed

A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.

Slack AI
AI assurance review required
1 blocking issue to resolve before signing
Assessed Sep 1, 2026 · public evidence coverage 33% · evidence confidence medium high · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

ISO/IEC 27001
Claimed & corroborated

Scope covers the ISMS supporting Slack Technologies, LLC and its Team Collaboration Platform. It does NOT name Slack AI specifically, so this is platform-level coverage rather than product-scoped. Certified by Schellman Compliance, LLC; original registration 10 Nov 2017, issue date 8 Jan 2026.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 27001:2022 certificate of registration published by Slack (Schellman Compliance, LLC, version 11) · checked Sep 1, 2026

Valid until Nov 9, 2026

ISO/IEC 27017
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27018
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
SOC 2
Vendor claimed only

Stated on the GDPR commitment page alongside SOC 3. No report or scope statement was available.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
SOC 3
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 42001
Claimed & corroborated

The certificate's scope names Slack AI explicitly, so the AI management system certification covers the assessed product rather than only its parent. Issued by MSECB, certificate CERT-001117, certified since 2025-09-30.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 42001:2023 certificate published by Salesforce/Slack (MSECB, certificate CERT-001117) · checked Sep 1, 2026

Valid until Sep 29, 2028

FedRAMP Authorization
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Sep 1, 2026

ISO/IEC 27701
Claimed & corroborated

27701 is carried as an extension of the same ISO/IEC 27001 certificate, in the role of a personally identifiable information processor. Platform-level, not scoped to Slack AI.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 27701:2019 extension recorded on Slack's ISO/IEC 27001:2022 certificate (Schellman Compliance, LLC) · checked Sep 1, 2026

Valid until Nov 9, 2026

IRAP
Claimed & corroborated

Australian instance of the Slack Cloud platform, assessed at PROTECTED against the ISM (December 2025) under the ACSC framework Phase 1a. An IRAP assessment is not an authorisation - the letter states cloud consumers remain responsible for granting an Authority to Operate in their own environment.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · IRAP Letter of Assessment published by Slack (CyberCX, 26 May 2026) · checked Sep 1, 2026

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Sep 1, 2026.