Built to keep your data safe.
Security and data protection are foundational to how Culture Engine is built and operated. This page provides transparent visibility into our security practices, data handling, and compliance documentation — everything your security and procurement teams need in one place.
- Slack-native
- TLS 1.2+ in transit
- DPA pre-signed
- Least-privilege scopes
- Data never sold
Questions? Email hello@cultureengine.ai — we reply within one business day.
Security at a glance
Slack-native
Runs inside Slack using the minimum permissions each feature needs — nothing “just in case.”
No message snooping
We can’t read your team’s direct messages or private channels the app hasn’t been added to.
No sensitive data
No payroll, banking, or payment-card data is ever collected.
Encrypted in transit
All traffic uses TLS 1.2 or higher, and file storage is encrypted at rest with AES-256.
DPA ready
A Data Processing Addendum is available and pre-signed for self-serve customers.
Delete on request
Full data deletion is available any time, confirmed to you in writing.
Slack permissions & access scopes
Culture Engine requests only the workspace permissions required to deliver product functionality. Each scope maps directly to a user-facing feature.
| OAuth scope | Purpose |
|---|---|
chat:write, chat:write.public | Post shoutouts, celebrations, and Weekly Recaps to your recognition channel |
commands | Run slash commands such as /shoutout |
users:read, users:read.email | Match teammates and route recognition — display names, profile photos, and work email |
channels:read, channels:manage, channels:join | Create and join the recognition channel when the app is installed |
channels:history, reactions:read, reactions:write | Read and react to replies on shoutouts the app itself posted |
files:read | Attach an image or video to a shoutout from the compose window |
im:write, im:read | Send you direct-message notifications, such as reward and Coin updates |
groups:read, mpim:read | Basic channel info for private and group channels the app is used in |
team:read | Read basic workspace info during install |
emoji:read | Show your workspace’s custom emoji |
What we store
- Member names and work email addresses
- Recognition messages and Coin balances
- Reward redemption records (reward type and date)
What we never access or store
- Your team’s direct messages
- Private channels the app has not been added to
- Payroll, compensation, or HR records
- Bank account or payment-card details — reward fulfillment is handled by Tremendous, and cardholder data never passes through Culture Engine systems
Where your data lives
Customer data is used only to operate the service. It’s never sold, and never shared with third parties for advertising.
- Hosting
- Amazon Web Services (AWS), United States
- Encryption in transit
- TLS 1.2 or higher, everywhere
- File storage at rest
- Amazon S3, encrypted with AES-256
- Network isolation
- Production database sits in a private network, off the public internet
- Environment separation
- Production runs on its own isolated infrastructure, separate from development
Who can touch your data
- Production access is limited to a small number of authorized engineers
- Two-factor authentication is enforced on all internal accounts
- Access follows the principle of least privilege — people get only what their role requires
- Access rights are reviewed on a regular basis
Who else processes your data
The companies below process data on our behalf under contractual data-protection safeguards, each running its own published security program. This list is maintained in line with our DPA.
Amazon Web Services
Cloud hosting, database, file storage, and transactional email
United StatesSlack
The workspace platform Culture Engine runs inside
United StatesTremendous
Reward and gift-card fulfillment
United StatesPostHog
Product analytics
United StatesWhop
Subscription billing and payments
United StatesGo High Level
Scheduling for demos and onboarding calls
United States
Retention & deletion
- Customer data is kept only as long as needed to run the service for active customers
- When you cancel, workspace data is deleted within 30 days of your request
- Deletion requests can be sent any time to hello@cultureengine.ai and are confirmed in writing
- Recognition history, Coin balances, and redemption records are all included in a deletion
Security questionnaire
A completed CAIQ-Lite is available on request; custom questionnaires returned promptly.
SOC 2
Our practices are documented on this page, and a completed CAIQ-Lite is available on request.
Report a vulnerability
We welcome reports from security researchers and customers. Report a suspected vulnerability to hello@cultureengine.ai, and we’ll acknowledge it within one business day, coordinate disclosure timelines with you, and credit researchers who’d like to be named.
Common questions
No. The app can only read replies on the shoutouts it has posted in the recognition channel it was added to. It can’t read your team’s direct messages or other private channels.
No. Customer data is used only to operate Culture Engine.
On Amazon Web Services (AWS) in the United States. Data is encrypted in transit with TLS 1.2 or higher.
Yes — see cultureengine.ai/dpa. It’s pre-signed for self-serve customers.
Yes. A completed CAIQ-Lite is available on request, and we return custom questionnaires promptly.
All workspace data is deleted within 30 days of your request, with written confirmation.
Not yet. Our security practices are documented on this page, and a completed CAIQ-Lite questionnaire is available on request.
Need something specific for your review?
Send us the questionnaire, the document, or the question. A real person replies within one business day.

