Security
Secure from Day 1
ClearFeed is built from the ground up by an experienced team with security, privacy, and compliance prioritized from day one. Audit and penetration test reports, as well as compliance-related policies, are available upon request via security@clearfeed.ai or via ClearFeed Trust Site
We are SOC2 Type 2 Certified
We are GDPR Compliant and HIPAA Compliant
We perform annual application-level penetration tests via an independent third party
All customer data is encrypted at rest and in transit, and access is protected behind your enterprise SSO
Signed DPA and BAA is available on request
Installing ClearFeed on Slack
You can safely install the ClearFeed App on your Slack Workspace by starting from the ClearFeed WebApp and authorizing the Slack installation during signup.

FAQs on ClearFeed Slack App
Why can't I install ClearFeed from the Slack App Directory?
Our Slack Marketplace application is currently under review and we are actively working with the Slack team to get ClearFeed listed. We will post the progress here as we get better visibility. You may see a banner when authorizing the app in Slack, but you can safely proceed with the installation from the ClearFeed WebApp.
What permissions does ClearFeed need in Slack?
The permissions required by ClearFeed will be shown by Slack as part of the "Authorize Slack" step. Please note that ClearFeed can only read/write messages in Slack channels it is explicitly added to.
What can I do if I am unable to install ClearFeed to the Slack workspace myself?
Many Slack workspaces restrict installation of apps to Admins only. Some restrict non‑marketplace apps so that only workspace owners (and not admins) can approve them. If you see an error asking you to "ask the owner/admin to add this app" when trying to authorize ClearFeed, you have two options:
Option 1: Continue with the Slack app install flow — Slack will automatically send a request to your workspace admin/owner for approval and wait for their approval
Option 2: Invite your workspace admin/owner to the ClearFeed account using the "Invite Workspace Admin" link shown in the Signup flow and ask them to install the Slack app themselves

What data from Slack do you store in ClearFeed and how long?
We only store data that is essential to providing our services. This includes messages in Slack shared with ClearFeed and user profile data from Slack. Note that ClearFeed does not store attachments posted in Slack. Our data storage and retention policy is available at https://docs.clearfeed.ai/clearfeed-help-center/account-setup/data-retention - admins can configure data retention to control how long messages in Slack are stored in ClearFeed.
Why does ClearFeed need to be installed to Slack for creating an account?
Access to ClearFeed accounts is currently restricted to members of the attached Slack workspace. This is why Slack installation is the first step in creating a ClearFeed account. We are working on relaxing this requirement in the near future.
Overview of Security on ClearFeed
Data Residency
Our infrastructure is primarily hosted on AWS in the
us-east-1region across three availability zones.Any infrastructure (example: search indexes) outside of AWS are also stored in US East region.
EU Resident data processing and storage is coming soon. Please contact support@clearfeed.ai for details.
Infrastructure Security
By default, we block all traffic at a network level and only open specific ports as required to deliver the ClearFeed service.
Any escalated access to infrastructure requires a VPN or a whitelisted IP with 2-factor authentication.
We use AWS GuardDuty to detect unusual traffic and unauthenticated access to our critical systems.
Host-based intrusion detection systems are in active use.
Data Encryption
All critical data that we store is encrypted at rest and in transit.
In addition, application level encryption is used for sensitive data.
Failover and disaster recovery
All of our production infrastructure is built with redundancies in place, in highly-available configurations spread over three different availability zones in the us-east-1 AWS region.
We have a disaster recovery plan which is reviewed every 6 months and a tabletop exercise is conducted by the management to verify that the plan is up to date.
Inventory and configuration
Infrastructure is kept as code using Terraform, and other infrastructure-as-code tools with changes going through a process very similar to the application-level software development process. We make use of separate infrastructure for development, staging, and live environments, with no sharing of data between environments.
Identity and Access Control
Access to all of our critical systems requires 2FA authentication to sign in.
Access to customer data is limited to authorized employees who require it for operational and maintenance activities.
Access to sensitive production data is limited to just the DevOps team.
Monitoring and logging
We do extensive monitoring of infrastructure and application performance, which usually allows us to detect issues before many customers experience them.
Automated alerts are set up with the help of Sentry. All alerts are acknowledged within 10 minutes.
Penetration Testing
We perform annual application-level penetration tests via an independent third party.
We aim to fix any discovered critical issues within 2 business days, and high-severity issues within 30 business days.
Medium-severity and lower-severity issues are handled as part of ongoing security work.
Incident response
ClearFeed implements a protocol for handling security events and other operational issues, including escalation procedures, rapid mitigation, and post-mortems.
You can visit our status page to get updates on potential issues, and even subscribe to automatic updates.
User Consent
We rigorously adhere to GDPR requirements, ensuring that all data processing activities meet the highest standards of security, transparency, and user consent mandated by EU regulations.
We obtain explicit consent from users before utilizing cookies, ensuring full compliance with GDPR guidelines.
Compliance
ClearFeed is SOC2 Type 2 compliant, GDPR compliant and HIPAA compliant.
We are not ISO27001 compliant at the moment.
Data retention
Users can configure data retention (from 7 to 365 days). When enabled, raw messages are deleted after this period.
ClearFeed does not store attachments from Slack.
Sensitive data redaction is configurable on Enterprise Plans.
You can read more about data retention here.
Single Sign-On
ClearFeed offers Single Sign-On via Google and Microsoft OAuth on all plans.
SAML-based SSO (compatible with Okta, JumpCloud and other providers) is available on Enterprise plans.
API Token Security
API tokens are automatically revoked when a Slack user is deleted or deactivated from the workspace
Account admins are notified when tokens are revoked due to user removal
See Developer Settings for details.
Terms of Service, Privacy Policies and DPA
Our standard policies are listed on our public website:
Terms of Service - https://clearfeed.ai/tos
Privacy Policy - https://clearfeed.ai/privacy-policy
Enterprise plans support custom DPA, Terms of Service, and Security Reviews. Please contact us over Slack or Email for any questions.
Security questions or issues? If you think you may have found a security vulnerability within ClearFeed, please get in touch with our security team.
Last updated
