TL;DR. SlackBridge does not currently hold its own SOC 2 or ISO 27001 attestation. Its controls are aligned with the SOC 2 Trust Service Criteria (Security, Availability and Confidentiality), and an independent third-party penetration test and formal attestations are on the roadmap. SlackBridge runs on infrastructure providers that hold SOC 2 Type II, ISO 27001 and PCI DSS certifications. A security questionnaire, policies and other due-diligence material are available from security@slackbridge.com.
The short version
- SOC 2: SlackBridge does not currently hold its own SOC 2 attestation (no SOC 2 Type I or Type II report). Its controls are aligned with the SOC 2 Trust Service Criteria for Security, Availability and Confidentiality.
- ISO 27001: SlackBridge does not currently hold its own ISO 27001 certification.
- On the roadmap: an independent third-party penetration test and formal attestations. The Trust Center is updated as that work completes.
- Infrastructure: SlackBridge runs on cloud and payments providers that hold SOC 2 Type II, ISO 27001, ISO 27018 and PCI DSS Level 1 certifications. SlackBridge inherits those infrastructure-layer controls and adds its own application-layer controls.
- For a vendor review: email security@slackbridge.com for a completed security questionnaire, full policies or other due-diligence material. Detailed documentation of the security controls is available to enterprise customers under NDA.
Does SlackBridge have a SOC 2 report?
No. SlackBridge does not currently hold its own SOC 2 attestation, so it cannot provide a SOC 2 Type I or Type II report. If your procurement process requires a third-party SOC 2 Type II report from the vendor today, SlackBridge does not meet that requirement yet.
What SlackBridge does have: a control set built on the SOC 2 Trust Service Criteria (Security, Availability and Confidentiality), an OWASP-aligned secure development process, and a written policy set reviewed at least annually. These are described on the Trust Center and the Security & Compliance page.
Does SlackBridge have ISO 27001, or a penetration test report?
SlackBridge does not currently hold its own ISO 27001 certification. An independent third-party penetration test and formal attestations are on the roadmap, and the Trust Center will be updated as that work completes.
What certifications does SlackBridge's infrastructure have?
SlackBridge's production infrastructure runs on cloud and payments providers that independently maintain SOC 2 Type II, ISO 27001, ISO 27018 and PCI DSS Level 1 certifications. SlackBridge runs on Cloudflare's infrastructure. Payments are handled by Stripe. The full list of companies that process data is on the Sub-Processors page.
These are the providers' certifications, not SlackBridge's own. They cover the infrastructure layer; SlackBridge's own application controls sit on top.
Which security controls does SlackBridge have?
The Trust Center lists them. In summary:
- No message content at rest. Messages are relayed and discarded; only one-way fingerprints and message-ID mappings are kept to keep threads in sync. See What data does SlackBridge store?.
- Encryption of data in transit and of stored access tokens.
- Per-organization isolation of every record.
- Tamper-evident audit log for security events, with an independent copy in object storage.
- Security checks on every deploy: static analysis, secret scanning and dependency auditing; a high-severity finding blocks the release.
Can SlackBridge sign a HIPAA BAA?
No. SlackBridge does not currently offer a HIPAA Business Associate Agreement (BAA).
What about GDPR and a data processing agreement?
SlackBridge's Privacy Policy describes how personal data is processed and how international transfers are safeguarded. The companies that process customer data are listed on the Sub-Processors page. For a data-processing addendum, email support@slackbridge.com.
How do I get a security questionnaire or other documents for a vendor review?
Email security@slackbridge.com and say what you need - for example a completed security questionnaire, the full policy set, or architecture details. Detailed documentation of SlackBridge's security controls is available to enterprise customers under NDA.
To report a security vulnerability, follow the vulnerability disclosure policy on the Trust Center.