Skip to content

Trust and security

We ask for real access. Here is exactly how we handle it.

Connecting an agent to your Slack or Teams workspace and your identity provider is a serious decision. This page is the honest version of what we request, what we refuse to request, and what happens to your data.

Trust

How we protect the data you give us

We are asking for access to your workspace directory and your cloud metadata, so the burden of proof is on us. Here is exactly how that access is scoped, stored and reviewed.

Least privilege by default

Connectors request the narrowest scopes that work: directory read, message send, and read-only cloud metadata. Nothing we do requires standing write access to your production systems.

Encrypted tokens, sealed and rotated

OAuth tokens and webhook secrets are sealed with envelope encryption in a managed KMS, scoped per workspace, and rotated on a schedule you can audit.

No training on your data

Your messages, findings, evidence and directory data are never used to train foundation models. Sub-processors are contractually prohibited from doing so either.

Data residency you choose

US, EU or UK regions on annual plans, with the ability to pin evidence storage to a jurisdiction and delete on request.

Human and machine review

Sensitive actions are human-gated. A reviewer must approve anything Sentinel sends to your executives before it reaches them, and you can require approval for every framework change.

SSO, audit logs and access reviews

SAML SSO with SCIM provisioning, immutable audit logs of every agent action and every admin change, and quarterly access reviews of our own team.

Need our own posture before you connect us?

We will share our control matrix, sub-processor list, penetration test summary and DPA under NDA. Ask us anything, including the awkward questions.

Permissions

Every scope we ask for, and why

If a permission is not on this list, we do not request it. Scopes are shown to your admin at install time and can be reviewed at any point afterwards.

Slack and Microsoft Teams permission scopes requested by CISO Express
ScopeWhy we need it
Directory read (users, groups, roles)To build the ownership graph and route asks to the right role.
Send direct messagesTo open the conversation with an owner and follow up.
Post in approved channelsTo log activity in the shared channel you nominate — never other channels.
Read replies in threads it startedTo capture the answer as evidence and close the loop.
Read channel membershipTo know who to escalate to when the owner does not respond.

What we do not do

  • No access to private channels you have not approved
  • No access to employee-to-employee direct messages
  • No ability to delete, edit or export your messages
  • No write access to production systems, cloud accounts or repositories
  • No endpoint agents and no access to employee devices

Controls

The controls behind the promises

These are the practices we hold ourselves to, whether or not you ask about them during procurement.

Encryption

  • TLS 1.3 in transit for every connection, including Slack and Teams webhooks
  • AES-256 at rest for storage and backups
  • Envelope encryption for OAuth tokens and secrets via a managed KMS
  • Per-workspace key scoping, rotated on a documented schedule

Access control inside our team

  • Least privilege with just-in-time elevation for production access
  • Mandatory hardware-backed MFA for every employee and contractor
  • Quarterly access reviews of our own systems
  • Automated joiner and leaver workflows with a 24-hour revocation target

Monitoring and response

  • Immutable audit logs of every agent action and admin change
  • Alerting on anomalous agent behaviour, bulk sends and scope changes
  • Documented incident response plan with a 1-hour acknowledgement target
  • Customer notification within 72 hours of a confirmed data breach

Data lifecycle

  • Region pinning to US, EU or UK on annual plans
  • Configurable retention windows down to 30 days for message content
  • Evidence export as a signed archive you control
  • Deletion of workspace data within 7 days of a verified request

Sub-processors

We keep this list short on purpose. Each sub-processor is bound by a written agreement that includes confidentiality, security obligations and a prohibition on using your data to train models. You get 30 days notice before a new one is added to a plan you are on.

  • Cloud infrastructure

    Hosting, storage, networking and key management

  • Model provider

    Language understanding under a zero-retention, no-training agreement

  • Email delivery

    Transactional email such as workspace setup confirmation and digests

  • Error monitoring

    Crash and error telemetry with payload scrubbing enabled

Reporting a vulnerability

We welcome reports from researchers. Email security@ciso.express with steps to reproduce; we acknowledge within one business day and will not pursue legal action against good-faith research.

Email the security team

Put an owner on every issue

Start free, connect Slack or Teams, and Sentinel assigns the first issues before you commit to anything.