Built to keep your data safe.
Security and data protection are foundational to how Culture Engine is built and operated. This page provides transparent visibility into our security practices, data handling, and compliance documentation — everything your security and procurement teams need in one place.
- Slack-native
- TLS 1.2+ in transit
- DPA pre-signed
- Least-privilege scopes
- Data never sold
Questions? Email hello@cultureengine.ai — we reply within one business day.
Security at a glance
Slack-native
Runs inside Slack using the minimum permissions each feature needs — nothing “just in case.”
No message snooping
We can’t read your team’s direct messages or private channels the app hasn’t been added to.
No sensitive data
No payroll, banking, or payment-card data is ever collected.
Encrypted end to end
TLS 1.2 or higher at all public edges, and database and file storage are both encrypted at rest.
DPA ready
A Data Processing Addendum is available and pre-signed for self-serve customers.
Delete on request
Full data deletion is available any time, confirmed to you in writing.
Slack permissions & access scopes
Culture Engine requests only the workspace permissions required to deliver product functionality. Each scope maps directly to a user-facing feature.
| OAuth scope | Purpose |
|---|---|
chat:write, chat:write.public | Post shoutouts, celebrations, and Weekly Recaps to your recognition channel |
commands | Run slash commands such as /shoutout |
users:read, users:read.email | Match teammates and route recognition — display names, profile photos, and work email |
channels:read, channels:manage, channels:join | Create and join the recognition channel when the app is installed |
channels:history, reactions:read, reactions:write | Read and react to replies on shoutouts the app itself posted |
files:read | Attach an image or video to a shoutout from the compose window |
im:write, im:read | Send you direct-message notifications, such as reward and Coin updates |
groups:read, mpim:read | Basic channel info for private and group channels the app is used in |
team:read | Read basic workspace info during install |
emoji:read | Show your workspace’s custom emoji |
Some Slack scopes grant broader technical access than we use; our practice is limited to the recognition channel.
What we store
- Member names and work email addresses
- Recognition messages and Coin balances
- Reward redemption records (reward type and date)
What we never access or store
- Your team’s direct messages
- Private channels the app has not been added to
- Payroll, compensation, or HR records
- Bank account or payment-card details — reward fulfillment is handled by Tremendous, and cardholder data never passes through Culture Engine systems
Where your data lives
Customer data is used only to operate the service. It’s never sold, and never shared with third parties for advertising.
- Hosting
- Amazon Web Services (AWS), United States
- Encryption in transit
- Customer data is encrypted in transit (TLS 1.2+) at all public edges
- Encryption at rest
- Database and file storage are encrypted at rest with AES-256
- Network isolation
- Production database sits in a private network, off the public internet
- Environment separation
- Production runs on its own isolated infrastructure, separate from development
Backups & operations
How the service is backed up, monitored, and changed.
- Backups & DR
- Production runs automated backups with point-in-time recovery, and deletion protection is enabled
- Recovery
- Recovery today is restore-from-backup
- Logging & monitoring
- Centralized application logging, metrics, and distributed tracing are in place, with automated alerting routed to the team in real time
- Change management
- All changes ship through peer-reviewed pull requests and automated CI/CD. No direct-to-production changes.
Who can touch your data
- Production access is limited to a small number of authorized engineers
- Two-factor authentication is enforced on all internal accounts
- Access follows the principle of least privilege — people get only what their role requires
Who else processes your data
The companies below process data on our behalf under contractual data-protection safeguards, each running its own published security program. This list is maintained in line with our DPA.
Amazon Web Services
Cloud hosting, database, file storage, and transactional email
United StatesSlack
The workspace platform Culture Engine runs inside
United StatesTremendous
Reward and gift-card fulfillment
United StatesPostHog
Product analytics
United StatesWhop
Subscription billing and payments
United StatesGo High Level
Scheduling for demos and onboarding calls
United States
Retention & deletion
We retain data while your workspace is active. On a deletion request (any time, to hello@cultureengine.ai), all workspace data is erased within 30 days and confirmed in writing. Canceling your subscription downgrades your workspace but does not by itself delete data.
International data transfers
Culture Engine is an Australian entity and hosts customer data on AWS in the United States, so data originating in the EEA, the United Kingdom, or Switzerland is transferred across borders. Where the destination country is not recognized as providing adequate protection, those transfers rely on the Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Agreement, or an equivalent lawful mechanism — incorporated by reference in section 13 of our DPA.
Incidents & breach notification
Production issues trigger automated alerts to the team. We publish a channel for external vulnerability reports and commit to acknowledging within one business day.
If we confirm a personal data breach affecting your data, we notify you without undue delay — including what happened, which categories of data and people were affected, the likely consequences, and what we are doing about it. This commitment is contractual, set out in section 12 of our DPA.
Security questionnaire
Send us a CAIQ, your own template, or a portal invite — we complete and return it promptly.
SOC 2
Our practices are documented on this page, and we complete security questionnaires on request.
Report a vulnerability
We welcome reports from security researchers and customers. Report a suspected vulnerability to hello@cultureengine.ai, and we’ll acknowledge it within one business day, coordinate disclosure timelines with you, and credit researchers who’d like to be named.
Common questions
No. The app can only read replies on the shoutouts it has posted in the recognition channel it was added to. It can’t read your team’s direct messages or other private channels.
No. Customer data is used only to operate Culture Engine.
On Amazon Web Services (AWS) in the United States. Data is encrypted in transit with TLS 1.2 or higher at all public edges, and database and file storage are both encrypted at rest.
Yes — see cultureengine.ai/dpa. It’s pre-signed for self-serve customers.
Yes. Send us a CAIQ, your own template, or a portal invite and we complete and return it promptly.
Canceling downgrades your workspace but does not delete your data on its own. Email hello@cultureengine.ai to request deletion — all workspace data is erased within 30 days and confirmed to you in writing.
Not yet. Our security practices are documented on this page, and we complete security questionnaires on request.
Need something specific for your review?
Send us the questionnaire, the document, or the question. A real person replies within one business day.

