VendorScore · Data-access posture
Plain-language data-access score from Slack’s public trust docs — EKM included. Strong SOC 2 ≠ zero-knowledge.
Join waitlist for full PDF All vendorsPublic documentation review only. Not a pen test. Not legal advice. Evidence dated 2026-10-06.
Clear answer
Yes, Slack can read your data by design — even with EKM. EKM improves custody and revoke, not zero-knowledge.
Scored config: Enterprise Grid/Enterprise+ with Slack EKM (customer AWS KMS). Evidence 2026-10-06.
| Dimension | Score |
|---|---|
| Key custody | 58 |
| Plaintext access | 42 |
| Encryption claims | 68 |
| Subprocessors | 55 |
| Auditability | 88 |
| Overall (equal-weight average) | 62 |
Higher = better customer control / less inherent vendor plaintext access for the scored configuration. Strong compliance ≠ no read access.
Yes, by design. Even with Slack EKM, Slack uses your keys to serve messages and files. EKM improves key custody and revoke, not zero-knowledge. VendorScore rates Slack 62/100 overall on Enterprise Grid/Enterprise+ with EKM, based on public trust docs (evidence 2026-10-06).
No. EKM puts encryption keys in your AWS KMS and improves custody and revoke. Slack still decrypts with authorized key use to run search, notifications, and the product. It is not end-to-end or zero-knowledge messaging.
Five equal-weight dimensions (0–100): key custody (58), plaintext access (42), encryption claims (68), subprocessors (55), and auditability (88). Overall 62. Public documentation review only — not a pen test and not legal advice.
Full write-ups with source lists are not for sale yet. Join the waitlist — delivered by email when ready. No Stripe checkout on this page. No calls.
Join waitlist for full PDF