Trust Center

Built to keep your data safe.

Security and data protection are foundational to how Culture Engine is built and operated. This page provides transparent visibility into our security practices, data handling, and compliance documentation — everything your security and procurement teams need in one place.

  • Slack-native
  • TLS 1.2+ in transit
  • DPA pre-signed
  • Least-privilege scopes
  • Data never sold

Questions? Email hello@cultureengine.ai — we reply within one business day.

Overview

Security at a glance

  • Slack-native

    Runs inside Slack using the minimum permissions each feature needs — nothing “just in case.”

  • No message snooping

    We can’t read your team’s direct messages or private channels the app hasn’t been added to.

  • No sensitive data

    No payroll, banking, or payment-card data is ever collected.

  • Encrypted in transit

    All traffic uses TLS 1.2 or higher, and file storage is encrypted at rest with AES-256.

  • DPA ready

    A Data Processing Addendum is available and pre-signed for self-serve customers.

  • Delete on request

    Full data deletion is available any time, confirmed to you in writing.

Application security

Slack permissions & access scopes

Culture Engine requests only the workspace permissions required to deliver product functionality. Each scope maps directly to a user-facing feature.

OAuth scopePurpose
chat:write, chat:write.publicPost shoutouts, celebrations, and Weekly Recaps to your recognition channel
commandsRun slash commands such as /shoutout
users:read, users:read.emailMatch teammates and route recognition — display names, profile photos, and work email
channels:read, channels:manage, channels:joinCreate and join the recognition channel when the app is installed
channels:history, reactions:read, reactions:writeRead and react to replies on shoutouts the app itself posted
files:readAttach an image or video to a shoutout from the compose window
im:write, im:readSend you direct-message notifications, such as reward and Coin updates
groups:read, mpim:readBasic channel info for private and group channels the app is used in
team:readRead basic workspace info during install
emoji:readShow your workspace’s custom emoji

What we store

  • Member names and work email addresses
  • Recognition messages and Coin balances
  • Reward redemption records (reward type and date)

What we never access or store

  • Your team’s direct messages
  • Private channels the app has not been added to
  • Payroll, compensation, or HR records
  • Bank account or payment-card details — reward fulfillment is handled by Tremendous, and cardholder data never passes through Culture Engine systems
Infrastructure

Where your data lives

Customer data is used only to operate the service. It’s never sold, and never shared with third parties for advertising.

Hosting
Amazon Web Services (AWS), United States
Encryption in transit
TLS 1.2 or higher, everywhere
File storage at rest
Amazon S3, encrypted with AES-256
Network isolation
Production database sits in a private network, off the public internet
Environment separation
Production runs on its own isolated infrastructure, separate from development
Access control

Who can touch your data

  • Production access is limited to a small number of authorized engineers
  • Two-factor authentication is enforced on all internal accounts
  • Access follows the principle of least privilege — people get only what their role requires
  • Access rights are reviewed on a regular basis
Sub-processors

Who else processes your data

The companies below process data on our behalf under contractual data-protection safeguards, each running its own published security program. This list is maintained in line with our DPA.

Data lifecycle

Retention & deletion

  • Customer data is kept only as long as needed to run the service for active customers
  • When you cancel, workspace data is deleted within 30 days of your request
  • Deletion requests can be sent any time to hello@cultureengine.ai and are confirmed in writing
  • Recognition history, Coin balances, and redemption records are all included in a deletion
Compliance

Documentation

To request any document, email hello@cultureengine.ai.

Available

Data Processing Addendum (DPA)

Pre-signed for self-serve customers.

Read the DPA
On request

Security questionnaire

A completed CAIQ-Lite is available on request; custom questionnaires returned promptly.

Not yet certified

SOC 2

Our practices are documented on this page, and a completed CAIQ-Lite is available on request.

Disclosure

Report a vulnerability

We welcome reports from security researchers and customers. Report a suspected vulnerability to hello@cultureengine.ai, and we’ll acknowledge it within one business day, coordinate disclosure timelines with you, and credit researchers who’d like to be named.

FAQ

Common questions

  • No. The app can only read replies on the shoutouts it has posted in the recognition channel it was added to. It can’t read your team’s direct messages or other private channels.

  • No. Customer data is used only to operate Culture Engine.

  • On Amazon Web Services (AWS) in the United States. Data is encrypted in transit with TLS 1.2 or higher.

  • Yes — see cultureengine.ai/dpa. It’s pre-signed for self-serve customers.

  • Yes. A completed CAIQ-Lite is available on request, and we return custom questionnaires promptly.

  • All workspace data is deleted within 30 days of your request, with written confirmation.

  • Not yet. Our security practices are documented on this page, and a completed CAIQ-Lite questionnaire is available on request.

Need something specific for your review?

Send us the questionnaire, the document, or the question. A real person replies within one business day.

Contact sales