SaaS Ranking

Slack

slack.com · Team chat and group messaging · checked 2026-09-15

30/100EBand E

Rank 2 of 5 in Team chat and group messaging, where the median is 26.

We measured 12 of 12 criteria for Slack on 2026-09-15. We found 5 with a source and did not find 7 at the addresses we checked. That is a transparency score of 30 out of 100, band E.

Overview

0 days since the newest finding, 0 since the oldest. 12 of 12 criteria measured in the last 30 days.

Evidence freshness is a statement about our measurement and is kept apart from the transparency score, which is frozen at v1. How good our own measurement is.

Transparency labelsaas-ranking.com

Slack

slack.com · Team chat and group messaging

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
E 30of 100 Rank 2 of 5

Published commitments3 of 9 found

Measured behaviour2 of 3 found

Checked 2026-09-15. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

The evidence pack carries every criterion with its source, the addresses we checked, the date and the data snapshot id – the four things a procurement file needs and a screenshot loses. We do not issue badges: a badge is the first step towards a paid placement, and there is none here.

The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.

Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Slack has no such document.

Where Slack sits in Team chat and group messaging

  1. A0 0%
  2. B0 0%
  3. C0 0%
  4. D1 20%
  5. E2 40%
  6. F2 40%
5 vendors with a score. Bands have fixed thresholds, see how the score works.

The band of Slack is marked. Vendors without a score are the ones where we could measure too few criteria to rank them – a gap on our side, counted separately.

What they state

The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.

Gaps, heaviest first

Data processing agreement

weight 3 of 3

No data processing agreement found.

Checked 8 addresses on 2026-09-15.

Show the 8 addresses we checked
  1. https://slack.com/legal/dpa – reached, no match (HTTP 404)
  2. https://slack.com/dpa – reached, no match (HTTP 404)
  3. https://slack.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  4. https://slack.com/data-processing-agreement – reached, no match (HTTP 404)
  5. https://slack.com/legal/data-processing-addendum – reached, no match (HTTP 404)
  6. https://slack.com/legal/gdpr – reached, no match (HTTP 404)
  7. https://slack.com/trust/dpa – reached, no match (HTTP 404)
  8. https://slack.com/privacy/dpa – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Subprocessor list

weight 3 of 3

No subprocessor list found.

Checked 7 addresses on 2026-09-15.

Show the 7 addresses we checked
  1. https://slack.com/legal/subprocessors – reached, no match (HTTP 404)
  2. https://slack.com/subprocessors – reached, no match (HTTP 404)
  3. https://slack.com/sub-processors – reached, no match (HTTP 404)
  4. https://slack.com/legal/sub-processors – reached, no match (HTTP 404)
  5. https://slack.com/trust/subprocessors – reached, no match (HTTP 404)
  6. https://slack.com/privacy/subprocessors – reached, no match (HTTP 404)
  7. https://slack.com/legal/subprocessor-list – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Data location stated

weight 3 of 3

We found this behind a sign-in, so it is not published openly.

Seen at https://slack.com/trust/privacy/privacy-policy · checked 2026-09-15

Show the 7 addresses we checked
  1. https://slack.com/security – reached, no match (HTTP 200)
  2. https://slack.com/trust – reached, no match (HTTP 200)
  3. https://slack.com/legal/privacy – reached, no match (HTTP 404)
  4. https://slack.com/privacy – found, but behind a sign-in
  5. https://slack.com/privacy-policy – found, but behind a sign-in
  6. https://slack.com/compliance – reached, no match (HTTP 404)
  7. https://slack.com/legal/privacy-policy – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Status page with history

weight 2 of 3

No public status page found.

Checked 3 addresses on 2026-09-15.

Show the 3 addresses we checked
  1. https://status.slack.com/ – reached, no match (HTTP 200)
  2. https://slack.com/status – reached, no match (HTTP 200)
  3. https://slack.com.statuspage.io/ – Could not be fetched: fetch failed.

Is this wrong? Send us the URL

No third-party tracking before consent

weight 2 of 3

Third-party requests seen on the first load, before any interaction.

Checked 1 address on 2026-09-15.

Show the 1 address we checked
  1. https://slack.com/ – third-party requests before any interaction: a.slack-edge.com, a11179690159.cdn.optimizely.com, api.company-target.com, cdn.cookielaw.org, cdn3.optimizely.com, d34u8crftukxnk.cloudfront.net, fonts.gstatic.com, geolocation.onetrust.com, logx.optimizely.com, www.youtube-nocookie.com, www.youtube.com

Is this wrong? Send us the URL

Notice before subprocessors change

weight 2 of 3

No commitment to give notice before subprocessors change found.

Checked 8 addresses on 2026-09-15.

Show the 8 addresses we checked
  1. https://slack.com/legal/subprocessors – reached, no match (HTTP 404)
  2. https://slack.com/subprocessors – reached, no match (HTTP 404)
  3. https://slack.com/sub-processors – reached, no match (HTTP 404)
  4. https://slack.com/legal/dpa – reached, no match (HTTP 404)
  5. https://slack.com/dpa – reached, no match (HTTP 404)
  6. https://slack.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  7. https://slack.com/trust/subprocessors – reached, no match (HTTP 404)
  8. https://slack.com/legal/sub-processors – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Uptime SLA with a figure

weight 1 of 3

No uptime figure found.

Checked 6 addresses on 2026-09-15.

Show the 6 addresses we checked
  1. https://slack.com/legal/sla – reached, no match (HTTP 404)
  2. https://slack.com/sla – reached, no match (HTTP 404)
  3. https://slack.com/legal/service-level-agreement – reached, no match (HTTP 404)
  4. https://slack.com/trust/sla – reached, no match (HTTP 404)
  5. https://slack.com/uptime – reached, no match (HTTP 404)
  6. https://slack.com/legal/uptime-sla – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Evidence

The full source lists sit behind these two groups, so that the answer above stays readable.

Published, with a source 5

Public pricing

weight 2 of 3

Actual numbers on a public page.

Source: https://slack.com/pricing · checked 2026-09-15

HTTPS enforced with HSTS

weight 2 of 3

HTTP redirects to HTTPS and the HSTS header is set.

  • HSTS max-age 31536000 seconds (365 days).
    Show the exact wording

    max-age=31536000; includeSubDomains; preload

    Read at https://slack.com/
  • HSTS options includeSubDomains, preload.
    Show the 2 exact wordings

    max-age=31536000; includeSubDomains; preload

    Read at https://slack.com/

    max-age=31536000; includeSubDomains; preload

    Read at https://slack.com/

Source: https://slack.com/ · checked 2026-09-15

Certifications named

weight 1 of 3

SOC 2 or ISO 27001 named on a public page.

  • Named on that page FedRAMP (not counted: the sentence does not carry it), HIPAA (not counted: the sentence does not carry it), ISO/IEC 27001, ISO/IEC 27017 (unclear from the sentence), ISO/IEC 27018 (unclear from the sentence), ISO/IEC 27701 (unclear from the sentence), SOC 2 (unclear from the sentence), TISAX (unclear from the sentence). The sentence we kept does not carry this finding on its own, so it counts in no list and no figure.
    Show the 8 exact wordings

    Federal Risk and Authorization Management Program (FedRAMP) Slack is FedRAMP Moderate authorized to meet the compliance needs of organizations in the public s

    Read at https://slack.com/trust/security

    ernational security and data privacy standards Health Insurance Portability and Accountability Act (HIPAA) Slack can be configured for HIPAA compliance, including electronically protected health infor...

    Read at https://slack.com/trust/security

    k protects our organization and your data at every layer Compliance certifications and attestations ISO/IEC 27001 Information Security Management System (ISMS) Download certificate ISO/IEC 27017 Secur...

    Read at https://slack.com/trust/security

    s and attestations ISO/IEC 27001 Information Security Management System (ISMS) Download certificate ISO/IEC 27017 Security Controls for the Provision and Use of Cloud Services Download certificate ISO...

    Read at https://slack.com/trust/security

    te ISO/IEC 27017 Security Controls for the Provision and Use of Cloud Services Download certificate ISO/IEC 27018 Protection of Personally Identifiable Information (PII) Download certificate ISO/IEC 2...

    Read at https://slack.com/trust/security

    tificate ISO/IEC 27018 Protection of Personally Identifiable Information (PII) Download certificate ISO/IEC 27701 Privacy Information Management System (PIMS) Download certificate ISO/IEC 42001 Inform...

    Read at https://slack.com/trust/security

    IEC 42001 Information technology — Artificial intelligence — Management system Download certificate SOC 2 (Type Ⅱ) Trust Services Principles SOC 3 Service Organization Controls Download report GovSlac...

    Read at https://slack.com/trust/security

    authorization Trusted Information Security Assessment Exchange Scope-ID SHYV0T Assessment-ID AMHN37 TISAX and TISAX results are not intended for the general public.

    Read at https://slack.com/trust/security

Source: https://slack.com/trust/security · checked 2026-09-15

security.txt (RFC 9116)

weight 1 of 3

Served at /.well-known/security.txt.

Source: https://slack.com/.well-known/security.txt · checked 2026-09-15

Named privacy contact

weight 1 of 3

A data protection officer or a dedicated privacy address is named.

Source: https://slack.com/trust/privacy/privacy-policy · checked 2026-09-15

History

Not enough completed runs yet to draw a line. The next runs fill this in.

Compare

A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.