Slack AI Vendor Risk Profile

Enterprise messaging and collaboration platform owned by Salesforce. Offers AI-powered features including Slack AI for channel summarization, thread digests, search answers, and workflow automation with LLM capabilities.

Visit Slack website

HQ: United States · Integrator

Risk overview

Risk score: 26/100

Risk tier: Moderate

Safety rating: 74/100 (higher is better)

Lower risk scores indicate lower assessed risk.

Last verified: Apr 19, 2026 (106 days ago) Aging · 8 cited sources

Risk dimensions

DimensionRisk score
Data Handling28/100
IP Exposure26/100
Jurisdiction13/100
Security30/100
Regulatory Compliance40/100
Transparency25/100
Business Stability31/100
Dependency Chain24/100
Agent GovernanceNot assessed

Analyst summary

Rating: Acceptable

Slack AI (now part of the Salesforce family) runs on closed LLMs within Slack's own AWS VPC, avoiding the third-party data-sharing exposure that most AI features introduce. Salesforce's compliance inheritance (SOC 2, ISO 27001, FedRAMP Moderate via GovSlack, HIPAA BAA on Enterprise Grid) makes this one of the stronger enterprise AI postures available.

Bottom line: One of the cleaner enterprise AI implementations available; good fit for Slack-standardized organizations.

Strengths

Concerns

Best for

Avoid if

Citations

  1. Data Handling — Hipaa Baa Available (primary · high confidence)
    https://slack.com/trust/compliance/hipaa
    Verified 2026-04-19
    Slack offers HIPAA Business Associate Agreements for Enterprise Grid customers on eligible plans.
  2. Data Handling — Third Party Data Sharing (primary · high confidence)
    https://slack.com/trust/compliance/slack-ai-security
    Verified 2026-04-19
    Slack AI runs on closed LLMs hosted within Slack's AWS VPC; customer data is not sent to third-party LLM providers.
  3. Data Handling — Trains On User Data (primary · high confidence)
    https://slack.com/trust/data-management/privacy-principles
    Verified 2026-04-19
    Slack does not train Slack AI or generative AI models on customer data. Customer data stays within the customer's Slack workspace.
  4. Ip Profiles — User Owns Outputs (primary · high confidence)
    https://slack.com/main-services-agreement
    Verified 2026-04-19
    As between Customer and Salesforce, Customer retains all ownership rights in Customer Data, including Slack AI generated summaries derived from Customer Data.
  5. Jurisdiction Profiles — Incorporation Country (official · high confidence)
    https://investor.salesforce.com/sec-filings/
    Verified 2026-04-19
    Slack Technologies LLC is a subsidiary of Salesforce, Inc., a Delaware corporation headquartered in San Francisco, California.
  6. Security Compliance — Fedramp Authorized (primary · high confidence)
    https://slack.com/trust/compliance/fedramp
    Verified 2026-04-19
    Slack holds FedRAMP Moderate authorization for its GovSlack offering.
  7. Security Compliance — Iso 27001 (primary · high confidence)
    https://slack.com/trust/compliance
    Verified 2026-04-19
    Slack holds ISO/IEC 27001, 27017, and 27018 certifications.
  8. Security Compliance — Soc2 Type2 (primary · high confidence)
    https://slack.com/trust/compliance
    Verified 2026-04-19
    Slack maintains SOC 2 Type II attestations available via Salesforce's Compliance portal.