Salesforce Slack
Slack brings the team together, wherever you are. With over 12 million daily users, Slack is the AI powered, channel-based messaging platform that brings your communication and tools into one place so your teams stay productive and informed. Slack has teams in London and Dublin.
Features
- Channel Architecture: Organises conversations into dedicated, searchable public/private spaces.
- API/Integrations: Connects thousands of apps and custom services easily.
- Enterprise Search: Indexes messages and files for powerful, quick retrieval.
- Workflow Builder: Automates tasks and internal processes using no-code tools.
- Real-Time Huddles: Provides audio, video calls, and screen sharing capability.
- Data Encryption: Data at rest and in transit for security.
- Slack Connect: Enables secure, direct collaboration with external organizations.
- AI Summarization: AI instantly summarizes long threads and channel conversations.
- Persistent History: Stores all message and file history without deletion.
- Mobile Clients: Offers full-featured apps for consistent access across devices.
Benefits
- Faster Decisions: Real-time channels enable quick consensus.
- Centralised Work: All communication and documents in one location.
- Reduces Email: Moves internal messages out of inboxes.
- Improves Visibility: Public channels ensure transparency and prevent silos.
- Automates Tasks: Workflows automate repetitive steps efficiently.
- Focuses Work: Dedicated channels for specific topics.
- Better Morale: Fosters informal communication and team connections.
- External Links: Securely collaborate with clients in shared channels.
- Quick Answers: Immediate support from the right experts.
- Work Flexibility: Full access from any mobile location.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 2 4 1 4 3 6 5 1 2 8 8 7 3 3
Contact
XMA LIMITED
Nancy Clayton-Schofield
Telephone: 0115 846 4000
Email: bidteam@xma.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Virtual Event Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
-
- Software Licenses: Valid operating system license for Windows macOS Linux
- Security Software: Enterprise antivirus or endpoint protection must be installed
- Network Security: Firewall configured to allow Slack domains WebSocket connections
- Email System: Corporate email for user authentication invitation workflows required
- Identity Provider: SSO or SAML for Enterprise Grid authentication required
- Mobile Management: EMM or MDM solution for managing Slack devices
- Data Loss Prevention: DLP tools compatible with Slack content monitoring
- Archiving Solution: Third party archiving eDiscovery tools for regulatory compliance
- Proxy Configuration: Corporate proxy settings configured for Slack API traffic
- Admin Access: IT administrator privileges required for workspace setup management
User support
- Email or online ticketing support
- Yes
- Support response times
- Slack provides 24/7 support on paid plans. With a 4h first response time on Slack Business+ and Enterprise+ plans.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Our webchat products have been assessed against WCAG 2.2 standards. Details of this compliance are described in our Voluntary Product Accessibility Template (VPAT) statements (available at: https://www.salesforce.com/company/legal/508_accessibility/). While formal usability studies with assistive technology have not been conducted, the services have been robustly assessed against WCAG 2.2. Furthermore, existing customers have successfully conducted testing and are utilizing the Salesforce Webchat capability in live services.
- Onsite support
- No
- Support levels
- N/A
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
For larger customers, Slack's Customer Success team advises and guides a wide variety of customers, ensuring they launch Slack successfully, adopt it widely and are continually driving business value from Slack.
Slack's Help Center (https://get.slack.help/hc/en-us) provides user assistance including the ability to raise customer support requests.
Slack offers online learning capabilities at https://get.slack.help/hc/en-gb/articles/218080037-Getting-started-for-new-members. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Workspace Owners and Admins can export data from their workspace. Your export option depends on your Slack plan.
Full details are available at https://get.slack.help/hc/en-gb/articles/201658943-Export-your-workspace-data. - End-of-contract process
-
Please refer to the response to the end-of-contract data extraction question above. Customers have access to their data at no additional cost.
Slack does not provide exit / transition services to support migration to future platforms or services.
Export capabilities are available at https://get.slack.help/hc/en-gb/articles/201658943-Export-your-workspace-data - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Both (mobile and desktop) offer the same capabilities. The differences are in how, as the mobile app's experience is tailored towards on-the-go access following the iOS and Android standards.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Slack users can read and write data Web, RTM, and Events APIs.
The Web API (https://api.slack.com/web) interface queries information to and from a Slack workspace.
The Real-Time Messaging API (https://api.slack.com/rtm) is a WebSocket-based API to receive events from Slack in real-time and send messages as users.
The Events API (https://api.slack.com/events-api) is a way to build apps and bots that respond to Slack activities.
Customers on the Business+ and Enterprise+ plans can provision and manage user accounts and groups with the Slack SCIM API (https://api.slack.com/scim).
For more information on our APIs, including limitations (e.g. rate limiting), see our API site (https://api.slack.com/). - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Slack provides a comprehensive Voluntary Product Accessibility Template (VPAT) that details their WCAG 2.2 compliance status. Providing accessibility support for
● Zoom settings in Slack on the web and desktop apps.
● Improved keyboard accessibility & navigation.
● Screen reader experience for the browser and desktop experiences.
● Support for large text on iOS and Android.
● Support for Dark Mode
More details available on https://slack.com/intl/en-gb/accessibility - API
- Yes
- What users can and can't do using the API
-
Slack users can read and write data via Web, RTM, MCP, and Events APIs.
The Web API (https://api.slack.com/web) interface queries information to and from a Slack workspace.
The Real-Time Messaging API (https://api.slack.com/rtm) is a WebSocket-based API to receive events from Slack in real-time and send messages as users.
The Events API (https://api.slack.com/events-api) is a way to build apps and bots that respond to Slack activities.
Customers on the Plus plan can provision and manage user accounts and groups with the Slack SCIM API (https://api.slack.com/scim).
For more information on our APIs, including limitations (e.g. rate limiting), please see our API site (https://api.slack.com/). - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Slack interface can be customise to meet user's preferences over channel sorting, color theme, font size and style, language, notifications etc.
Additionally Slack as platform can be enhanced by integrating it with apps from the Slack App Directory (ie: Integrating with Google Drive or Microsoft Sharepoint, etc)
Custom built apps can also be installed to run custom processes for the organisation
Scaling
- Independence of resources
-
Slack utilises services provided by its hosting providers (AWS and GCP) to distribute its production operation. Production transactions are replicated among these discrete operating environments, to protect the availability of Slack’s service.
In addition, most aspects of the Slack platform are rate limited. Given the variety of different kinds of inbound and outbound APIs made available, how and when rate limiting occurs differs between features.
Slack systems are capable of auto scaling based on demand so no users are impacted by the usage of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The Slack analytics dashboard allows you to gain insight into how your organisation uses Slack. From the dashboard, you can easily find and sort information to understand more about the activity in your workspace or Enterprise organisation. Including usage for individual features (workflows, AI, messaging, Huddles, canvases etc) to gain insights on how people collaborate and work together
- Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Salesforce
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Organisations can export data from their Slack workspace or Enterprise organisation tenant. Depending on the Slack subscription, they may also have additional export options available.
See the table with the export capabilities of each plan:
https://slack.com/intl/en-gb/help/articles/201658943-Export-your-workspace-data
Workspace owners and admins can export messages and file links from public channels in JSON format. - Data export formats
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CSV
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The Salesforce Slack Services are designed with the concept of continuous improvement and Trust (e.g. Availability, Performance and Security) in the infrastructure. Salesforce uses commercially reasonable efforts to make its on-demand services available to its customers 24/7, except for (minimal) planned downtime, for which Salesforce gives customers prior notice, and force majeure events. This service leverages Public Cloud region, and uses multiple availability zones. This pattern allows services to withstand up to two different zonal faults and continue to be available. Live and historical statistics on Salesforce system performance are publicly published at: https://trust.salesforce.com/en/#systemStatus.
- Approach to resilience
-
Slack utilises services from AWS to distribute its production operation across four separate physical locations. These four locations are within one geographic region, but protect Slack’s service from loss of connectivity, power infrastructure and other common location-specific failures. Production transactions are replicated among these discrete operating environments, to protect the availability of Slack’s service in the event of a location-specific catastrophic event.
Slack also retains a full backup copy of production data in a remote location from the location of the primary operating environment. Full backups are saved to this remote location once per day and transactions are saved continuously. Slack tests backups at least quarterly to ensure they can be correctly restored. - Outage reporting
-
Outage escalation policies are established and maintained as Salesforce's goal is to rapidly restore service. In the event of an extended outage, periodic updates are provided in near real time to customers via the trust.salesforce.com dashboard site.
Slack's System Status site gives real time updates on any incidents impacting the service and the ability to subscribe to updtes: https://slack-status.com/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Slack adheres to the principle of least privilege—workers are only authorized to access data that they reasonably must handle in order to fulfill their current job responsibilities.
Slack employs multi-factor authentication for administrative access to systems with more highly classified data. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO27017,
ISO27018,
SOC2 ,
SOC3 Reports. - Information security policies and processes
-
Salesforce's Information Security Management System (ISMS) and information security policies are based on the ISO 27002 framework of best practices and are ISO 27001 certified.
As required by this certification, the ISMS is endorsed by Senior Management. The Chief Trust Officer/CISO has responsibility for the information security policies and ISMS. The Salesforce Security Steering Committee approves/authorizes all changes to the policies, the Statement of Applicability (SoA), the information security manual, and any separate policy statements.
During the ISO 27001 audit process (as well as other audits such as SOX and SSAE 18 SOC 1), senior management for various departments are involved in verifying that policies and procedures are in place and adhered to. Policies are reviewed/approved at least annually.
Company wide security awareness training highlights the importance of the security policies to employees and reinforces the company’s number 1 value of Trust. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Changes to infrastructure components are made through code using industry standard Infrastructure as Code (IaC) software and assessed for their security impact before being deployed. Individuals who wish to deploy an IaC change into production are required to follow defined procedures and standards, and to complete mandatory change management training before participating in the change management process. A change must be approved and routed through the change owner before the change can be implemented. A ticketing system is used as part of the change management procedure which records the components and the changes made.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Salesforce includes threat modelling into its software development lifecycle to help ensure the risks associated with potential threats are mitigated as early as possible. Multiple threat intelligence sources are used to help understand the current and evolving threat landscape.
Vulnerability scans are performed on all Salesforce information systems and hosted applications. Patches are deployed in timeframes based on CVSS scores and risk level.
All vulnerabilities discovered during penetration tests are entered into the salesforce central ticketing system and are assigned an internal vulnerability ranking according on the OWASP risk rating framework based on likelihood and impact. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Salesforce Threat Intelligence and Detection team monitors the Salesforce services 24x7 for threats and unauthorized intrusions in collaboration with the Security Incident Response teams. Extensive logging and monitoring is conducted across all Salesforce Services and environments (at application, network and database layers). All suspicious activities are flagged and reported to Salesforce CSIRT for investigation, management, communication, and resolution of security events and incidents in line with the NIST Incident Response model.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Salesforce has an Incident Management Process that guides the Salesforce Computer Security Incident Response team in investigation, management and resolution activities which includes developing standard pre-defined procedures for dealing with common events.
Salesforce will promptly notify the customer in the event of any security breach of the Service resulting in an actual or reasonably suspected unauthorized disclosure of Customer Data. Notification may include phone contact by Salesforce support, email to customer's administrator and Security Contact and public posting on trust.salesforce.com.
Customers can email security@salesforce.com or use the https://security.salesforce.com/contact page to report incidents. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Slack offer a Free version of our product with limited features compared to paid plans. Customers can set up a Free workspaces and later choose to upgrade their free Worspace to a paid plan. For details see: https://app.slack.com/plans/
- Link to free trial
- https://app.slack.com/plans/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA Limited
- ISO/IEC 27001 accreditation date
- Thursday 27 November 2025
- What the ISO/IEC 27001 doesn’t cover
- The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the delivery, deployment and management of IT solutions, support and services in accordance with Statement of Applicability Version 4, and is audit against the new 2022 standard.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Limited
- ISO 9001 accreditation date
- Monday 17 February 2025
- What the ISO 9001 doesn’t cover
- The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the Delivery, Deployment and Management of IT Solutions, Support and Services.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Barclaycard
- PCI DSS accreditation date
- Thursday 9 January 2025
- What the PCI DSS doesn’t cover
- Our PCI DSS certification applies exclusively to payment processing systems and hosted payment gateways and does not extend to non‑payment systems, corporate IT infrastructure, or business applications outside the cardholder data environment.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B5f066ef-ff99-48a9-94b0-23f1f0ee595b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2d75659c-9df3-4d75-9406-9052a6e68c4b
- Other security certifications
- Yes
- Any other security certifications
- IASME CYBER ASSURANCE LEVEL ONE
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-