CompanyAten Security joins Anthropic's Cyber Verification ProgramRead the post →

Thoth · Slack integration

Slack integration privacy

This notice explains the information involved when your organization connects Slack to Aten Security’s Thoth service. Read it alongside Aten’s Privacy Policy and your organization’s agreement with Aten.

Information the integration receives

  • Workspace and installation identifiers, the installing user’s identifier, granted permissions, and credentials provided through Slack authorization.
  • The link between your Slack workspace and your Aten organization, configured channel identifiers, and delivery records such as Slack message identifiers.
  • Slack user identifiers and, when your organization identifies a recipient by email, the email lookup needed to deliver that notification.
  • Interaction payloads from buttons and forms, including workspace and user identifiers, message context, approval decisions, denial reasons, and policy exception details you submit.
  • Operational information needed to handle installation, delivery, errors, retries, and uninstall or credential-revocation events. An interaction payload can include message context even when a particular field is not used to make the decision.

How the information is used

Aten uses this information to connect the correct customer workspace, send Thoth alerts and explanations, check reviewer authorization, process submitted decisions and exception requests, and keep decision and delivery evidence. Review outcomes also form part of the Thoth feedback records used to evaluate and improve policy decisions.

Notifications can contain agent, tool, and decision context supplied by your Thoth deployment. Your organization chooses where those notifications are sent. People with access to the destination in Slack may be able to see that content. Slack processes information sent to it under its own terms and your workspace’s settings.

This integration does not scan general channel or direct-message history. Submitted interaction context and Thoth-generated messages are still processed as described above.

Retention and disconnecting Slack

Installation credentials support the active connection. Disconnecting or uninstalling the app disables that connection. It does not itself delete Thoth decision evidence, submitted exception records, or messages already posted in Slack.

The retention and deletion arrangements for Thoth records depend on your organization’s deployment and agreement with Aten. Slack applies your workspace’s retention settings to messages stored there. Contact Aten for the retention arrangements that apply to your organization, including operational records and backups.

Access, transfer, and deletion requests

Email legal@atensecurity.com to ask about access to, correction, transfer, or deletion of information handled by the integration. Include your organization and workspace name, and describe the request. Aten may need to verify your identity and coordinate with your organization’s administrator. Do not include Slack tokens, passwords, or sensitive agent payloads in the email.

You can use that address without an Aten account. It is also the contact for questions about applicable processing terms, service providers, retention, and this notice.