We take security seriously and follow best-practice principles:
Secure Data Storage: All data at rest is encrypted using AES-256, the most secure AES standard. Render is our hosting provider, with servers located in Germany.
Secure Data Transfer: All communications use TLS v1.2+ (rated Grade A in SSL Labs Report, as recommended by Slack).
Data Minimisation: We only request the minimum data needed to provide functionality. Importantly, Canopact never uses message-reading OAuth scopes.
Slack SSO: Authentication is entirely handled by Slack OAuth. No separate passwords are stored or required.
You can view our exact Slack scopes and detailed security information
here.