Trust Center

Built to keep your data safe.

Security and data protection are foundational to how Culture Engine is built and operated. This page provides transparent visibility into our security practices, data handling, and compliance documentation — everything your security and procurement teams need in one place.

  • Slack-native
  • TLS 1.2+ in transit
  • DPA pre-signed
  • Least-privilege scopes
  • Data never sold

Questions? Email hello@cultureengine.ai — we reply within one business day.

Overview

Security at a glance

  • Slack-native

    Runs inside Slack using the minimum permissions each feature needs — nothing “just in case.”

  • No message snooping

    We can’t read your team’s direct messages or private channels the app hasn’t been added to.

  • No sensitive data

    No payroll, banking, or payment-card data is ever collected.

  • Encrypted end to end

    TLS 1.2 or higher at all public edges, and database and file storage are both encrypted at rest.

  • DPA ready

    A Data Processing Addendum is available and pre-signed for self-serve customers.

  • Delete on request

    Full data deletion is available any time, confirmed to you in writing.

Application security

Slack permissions & access scopes

Culture Engine requests only the workspace permissions required to deliver product functionality. Each scope maps directly to a user-facing feature.

OAuth scopePurpose
chat:write, chat:write.publicPost shoutouts, celebrations, and Weekly Recaps to your recognition channel
commandsRun slash commands such as /shoutout
users:read, users:read.emailMatch teammates and route recognition — display names, profile photos, and work email
channels:read, channels:manage, channels:joinCreate and join the recognition channel when the app is installed
channels:history, reactions:read, reactions:writeRead and react to replies on shoutouts the app itself posted
files:readAttach an image or video to a shoutout from the compose window
im:write, im:readSend you direct-message notifications, such as reward and Coin updates
groups:read, mpim:readBasic channel info for private and group channels the app is used in
team:readRead basic workspace info during install
emoji:readShow your workspace’s custom emoji

Some Slack scopes grant broader technical access than we use; our practice is limited to the recognition channel.

What we store

  • Member names and work email addresses
  • Recognition messages and Coin balances
  • Reward redemption records (reward type and date)

What we never access or store

  • Your team’s direct messages
  • Private channels the app has not been added to
  • Payroll, compensation, or HR records
  • Bank account or payment-card details — reward fulfillment is handled by Tremendous, and cardholder data never passes through Culture Engine systems
Infrastructure

Where your data lives

Customer data is used only to operate the service. It’s never sold, and never shared with third parties for advertising.

Hosting
Amazon Web Services (AWS), United States
Encryption in transit
Customer data is encrypted in transit (TLS 1.2+) at all public edges
Encryption at rest
Database and file storage are encrypted at rest with AES-256
Network isolation
Production database sits in a private network, off the public internet
Environment separation
Production runs on its own isolated infrastructure, separate from development
Operations

Backups & operations

How the service is backed up, monitored, and changed.

Backups & DR
Production runs automated backups with point-in-time recovery, and deletion protection is enabled
Recovery
Recovery today is restore-from-backup
Logging & monitoring
Centralized application logging, metrics, and distributed tracing are in place, with automated alerting routed to the team in real time
Change management
All changes ship through peer-reviewed pull requests and automated CI/CD. No direct-to-production changes.
Access control

Who can touch your data

  • Production access is limited to a small number of authorized engineers
  • Two-factor authentication is enforced on all internal accounts
  • Access follows the principle of least privilege — people get only what their role requires
Sub-processors

Who else processes your data

The companies below process data on our behalf under contractual data-protection safeguards, each running its own published security program. This list is maintained in line with our DPA.

Data lifecycle

Retention & deletion

We retain data while your workspace is active. On a deletion request (any time, to hello@cultureengine.ai), all workspace data is erased within 30 days and confirmed in writing. Canceling your subscription downgrades your workspace but does not by itself delete data.

Data lifecycle

International data transfers

Culture Engine is an Australian entity and hosts customer data on AWS in the United States, so data originating in the EEA, the United Kingdom, or Switzerland is transferred across borders. Where the destination country is not recognized as providing adequate protection, those transfers rely on the Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Agreement, or an equivalent lawful mechanism — incorporated by reference in section 13 of our DPA.

Incident response

Incidents & breach notification

Production issues trigger automated alerts to the team. We publish a channel for external vulnerability reports and commit to acknowledging within one business day.

If we confirm a personal data breach affecting your data, we notify you without undue delay — including what happened, which categories of data and people were affected, the likely consequences, and what we are doing about it. This commitment is contractual, set out in section 12 of our DPA.

Compliance

Documentation

To request any document, email hello@cultureengine.ai.

Available

Data Processing Addendum (DPA)

Pre-signed for self-serve customers.

Read the DPA
On request

Security questionnaire

Send us a CAIQ, your own template, or a portal invite — we complete and return it promptly.

Not yet certified

SOC 2

Our practices are documented on this page, and we complete security questionnaires on request.

Disclosure

Report a vulnerability

We welcome reports from security researchers and customers. Report a suspected vulnerability to hello@cultureengine.ai, and we’ll acknowledge it within one business day, coordinate disclosure timelines with you, and credit researchers who’d like to be named.

FAQ

Common questions

  • No. The app can only read replies on the shoutouts it has posted in the recognition channel it was added to. It can’t read your team’s direct messages or other private channels.

  • No. Customer data is used only to operate Culture Engine.

  • On Amazon Web Services (AWS) in the United States. Data is encrypted in transit with TLS 1.2 or higher at all public edges, and database and file storage are both encrypted at rest.

  • Yes — see cultureengine.ai/dpa. It’s pre-signed for self-serve customers.

  • Yes. Send us a CAIQ, your own template, or a portal invite and we complete and return it promptly.

  • Canceling downgrades your workspace but does not delete your data on its own. Email hello@cultureengine.ai to request deletion — all workspace data is erased within 30 days and confirmed to you in writing.

  • Not yet. Our security practices are documented on this page, and we complete security questionnaires on request.

Need something specific for your review?

Send us the questionnaire, the document, or the question. A real person replies within one business day.

Contact sales