Slack Security & Privacy Scorecard
Android
Messages and activity pass through Amazon and Google infrastructure for delivery and machine learning features. Crash and error data is shared with Sentry. Account authentication runs through Google Play Services.
Best for
Teams wanting secure, reliable workplace messaging
Findings
- 0 critical
- 0 high
- 2 medium
- 3 low
- 3 info
1 issue identified across security and privacy analysis.
Top security issues
- SSL Error Bypass in Canvas Local Editor Mode
- Deep Link Handler Accepts External URLs
- JavaScript Interface in Canvas WebView
Top privacy issues
- Device ID and User ID in Internal Telemetry
- No Session Recording Active
- Firebase API Keys in String Resources
Full analysis
Slack
What This Means for You
Messages and activity pass through Amazon and Google infrastructure for delivery and machine learning features. Crash and error data is shared with Sentry. Account authentication runs through Google Play Services.
Recommendation: Trustworthy
Best For: Teams wanting secure, reliable workplace messaging
Key Findings
Data Security - 1 finding (1 info)
Network Security - 2 findings (1 medium, 1 info)
Code Safety - 0 findings
Privacy - 2 findings (1 low, 1 info)
Privacy Concerns
What Data is Collected
Slack collects account information, message content, and usage patterns to operate its workplace messaging and collaboration service. Crash reports and device diagnostics are also collected to maintain app stability.
Third-Party Data Sharing
User data is shared with the following third-party services:
- Sentry - Receives crash reports and error diagnostics from the device
- Amazon Chime SDK - Handles delivery of audio and video calls
- Firebase Cloud Messaging - Routes push notifications to the device
- Google ML Kit - Powers on-device machine learning features
- Google Play Services - Manages account sign-in
- Quip SDK - Supports document collaboration features
Understanding the Scores
| Category | Score |
|---|---|
| Security | 92/100 |
| Privacy | 100/100 |
| Data Security | 100/100 |
| Network Security | 88/100 |
| Code Safety | 90/100 |
| Data Collection | 100/100 |
| Data Sharing | 100/100 |
| User Control | 100/100 |
Positive Security Features
- Data security practices meet an exceptionally high standard throughout the app
- Privacy controls score at the maximum level, providing strong data ownership protections
- User control settings are comprehensive, allowing full management of account and data preferences
- Data collection and sharing practices are among the most restrained observed in enterprise messaging apps
Areas for Improvement
- A small number of network communication configurations could be tightened to further reduce the window for data to travel with less protection than expected during transit
- Minor data handling patterns were observed that, while common at enterprise scale, represent opportunities to limit data exposure at the edges
- Crash reporting to Sentry includes device and session context that could be scoped more narrowly to reduce the amount of information leaving the device
About This Analysis
Scores and findings are based on automated static analysis of the app's code and behavior. Results reflect observed practices at the time of analysis.
App Details
- App: Slack
- Package: com.Slack
- Version: 26.02.40.0 (Build 90015443)
- Scan Date: 2026-03-04
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 96/100 |