VendorScore · Team chat · Data-access posture
A plain-language answer from Slack's public trust docs, EKM included. A strong SOC 2 doesn't mean zero-knowledge.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-06, public docs only, not legal advice.
Short answer
Yes, Slack can read your data by design. Even with EKM, Slack has to use your keys to serve messages and files. EKM improves custody and revoke, not zero-knowledge.
Scored configuration: Enterprise Grid/Enterprise+ with Slack Enterprise Key Management (EKM, customer AWS KMS).
Without EKM (the default), Slack holds the keys and the report scores key custody and plaintext access lower.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
EKM keeps encryption keys in the customer's AWS KMS and covers messages, files, search index and canvases. Metadata such as channel names, profiles and filenames may stay on Slack-controlled keys.
Evidence: Slack EKM help articleEKM doesn't claim zero-knowledge. Slack decrypts with authorized key use to run search, notifications and apps, and that key use is logged in your CloudWatch/CloudTrail.
Evidence: Slack EKM product pageOur report flags these gaps in Slack's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, Slack can read your data by design. Even with EKM, Slack has to use your keys to serve messages and files. EKM improves custody and revoke, not zero-knowledge. VendorScore rates Slack 62/100 overall from public documentation (evidence dated 2026-10-06). Scored configuration: Enterprise Grid/Enterprise+ with Slack Enterprise Key Management (EKM, customer AWS KMS).
No. Slack encrypts customer data at rest and in transit by default, but it isn't end-to-end encrypted. EKM puts the keys for messages, files, search index and canvases in your AWS KMS, which improves custody and revoke, but Slack still decrypts with authorized key use to run search, notifications and the product. EKM is not zero-knowledge.
Access is policy-controlled, not cryptographically impossible. Slack doesn't publicly claim that staff cannot access Customer Data for support or operations, and its exact staff access procedures aren't fully public. Don't confuse this with your own admins: for example, Workspace Owners and Admins can export messages and file links from public channels. That is customer-side access, a separate question from Slack staff access.
Not for generative AI unless you opt in. Slack's privacy principles say: "Slack will not use Customer Data to train generative AI models unless Customer provides affirmative opt-in consent." Non-generative global ML models (such as suggestion features) are different: Slack says you can opt out of your Customer Data helping train them by having an Owner contact Slack's Customer Experience team.
VendorScore doesn't certify compliance; Slack publishes a DPA at https://slack.com/terms-of-service/data-processing. Slack's GDPR page says its standard DPA incorporates the EU Standard Contractual Clauses, and that through Salesforce, Slack participates in the EU-U.S. Data Privacy Framework.
Slack's subprocessor link (https://slack.com/slack-subprocessors) now points to Salesforce's Infrastructure and Sub-processors document (published October 2, 2026). For Slack, including Slack AI, it lists Amazon Web Services as the hosting provider. Slack Connect, apps and AI features can widen data paths, so check the current document for your setup.
Yes, for certain data at rest. Data residency for Slack lets teams choose the region where certain types of data at rest are stored, including Frankfurt (Germany) and Paris (France). Free and Pro workspaces must upgrade to Business+ first, all Slack data has to be in a single region, and some categories of data may be stored outside it.
Every URL cited on this page. Score and key findings: VendorScore report (slack.md), evidence dated 2026-10-06. FAQ policy links: vendor pages re-checked 2026-10-07.