whats-best.ai

Business Instant Messaging

Slack

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Salesforce, Inc. · slack.com

Compare with Mattermost → Compare with Microsoft Teams (Chat) → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Slack, from Salesforce, Inc. of San Francisco, scores most consistently on channels, threads & search, credited for channels, Slack Connect cross-organisation rooms, AI search over stored knowledge and unlimited message history from Pro. The sharpest split is integrations: the platform engineer gives 8 for a buildable platform with 1.7 million weekly active apps; the compliance counsel gives 4, finding no documented API, webhooks or rate limits in the evidence. Pricing transparency splits 2-5 similarly — tier boundaries are legible (SAML SSO from the free tier, DLP on every plan) but no per-user price appears in the evidence, so the annual invoice is not computable. The floor is deployment & data custody at 1-2: cloud-only, no self-hosting, no documented export format. Sovereignty sits at 2-3 — Germany residency purchasable only from Business+, subprocessors unnamed, LLMs in Slack's own AWS private cloud with no region stated. Persona-weighted totals span 4.0 to 4.9.

Report an error

Speaks for it

  • Slack Connect enables cross-organisation communication with admin-controlled external-connection policy
  • Message history is unlimited from Pro, with a documented 1-year cap on the free tier
  • SAML SSO is available down to the free tier, alongside 2FA and SCIM provisioning
  • Retention is configurable at workspace and channel level, with legal hold, audit logs and native DLP on every plan
  • Automations can be built with a click or by code, over an ecosystem of 1.7 million weekly active apps

Report an error

Held against it

  • Cloud-only with no self-hosting and no documented export format of any kind
  • No end-to-end encryption anywhere in the evidence, with vendor-held keys and Enterprise Key Management only as an add-on
  • No per-user price, billing period or VAT treatment appears in the captured pages, so the annual invoice is not computable
  • Germany data residency is available only from Business+ upward, and the subprocessor chain is unnamed
  • No documented API surface, webhooks, rate limits or sandbox appear in the evidence

Report an error

Best for

  • You need a mature channels-based daily messaging surface with real-time collaboration with external customers and partners
  • Your team runs on integrations such as Google Drive, ChatGPT, Asana and Workday, with per-workspace allow/restrict control over third-party services
  • You want basic AI (summaries, AI search) available across plans, starting at the free tier
  • You want to start on a free tier that still carries SAML SSO and native DLP

Report an error

Avoid if

  • You need self-hosting, a private instance, or a documented export of your archive as an exit path
  • You require end-to-end encryption or a plain statement of what the vendor itself can read
  • You must compute your annual invoice from published per-user prices before signing
  • You need Germany data residency below the Business+ tier, or a named subprocessor list for procurement

Report an error

The scores

Channels, threads & search

Show reasoning
How this is scored

The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.

0 — Flat group chats with no threads; search covers recent messages only, and history is capped.

3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.

5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.

8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.

10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.

Report an error

The Team Lead

Channels, Slack Connect, file sharing and search across the company's entire stored knowledge are evidenced, and history is unlimited from Pro upward — the daily surface works. But nothing in the evidence speaks to threads staying readable, edit history, pinned items, filtered search, or archiving a channel without losing its history, so the 'archive as knowledge base' half of the scale is unevidenced. 1 2 2

Report an error

The Security Officer

Channels, cross-organisation Slack Connect with boundaries, search over all stored company knowledge, and unlimited message history on paid plans with the free tier's 1-year cap documented clear the anchor-5 bar and half of anchor-8. But editing history, pinned/saved items, filtered search and human-readable conversation export are nowhere evidenced, so I stop short of 8. 1 2 2

Report an error

The Works Council Advocate

Channels, Slack Connect with 4M external users, file sharing and AI search across stored company knowledge are evidenced, with documented history limits (free: 1 year, paid: unlimited). But the evidence says nothing about threads, message edit history, or exporting a conversation a human can read — for a chat log to be a record, I need that archive story, not just search. 1 2 2

Report an error

The Compliance Counsel

Channels and Slack Connect with customer-controlled external boundaries, enterprise and AI-assisted search, and documented history limits (1 year on free, unlimited on paid) give a solid daily surface. But the evidence is silent on threads, message-editing history, and — the part I care about — any export of a conversation in a form a human or a court can read. 1 2 3 2

Report an error

The Platform Engineer

Slack Connect delivers genuine cross-organisation channels, unlimited message history on paid plans, and Enterprise/AI search across stored knowledge — real 8-anchor material. But edit history, pinned items, filtered search and channel lifecycle (archive/rename/merge) are nowhere in the evidence, so it tops out just under that anchor. 1 2 2

Report an error

The Skeptic

Channels, Slack Connect cross-organisation rooms with admin-controlled connection policy, AI search over stored knowledge, and — credit where due — a legible history cap: one year on Free, unlimited from Pro. But the words 'thread', 'edit history', 'pinned' and any human-readable export of a conversation appear nowhere in this registry, so I stop short of the 8 anchor. 1 2 3 2

Report an error

Encryption & access control

Show reasoning
How this is scored

What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.

0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.

3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.

5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.

8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.

10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.

Report an error

The Team Lead

Encryption at rest and in transit with vendor-held keys, SSO down to the free tier, 2FA, and an Enterprise Key Management add-on for customer-held keys — solid but conventional. No end-to-end encryption anywhere, no device verification or admin-revocable session management documented, and no plain statement of what Slack itself can read beyond promises about LLM training. 2 1 2

Report an error

The Security Officer

Encryption at rest and in transit with vendor-held keys, plus SSO, 2FA, SCIM, information barriers and channel posting permissions — that is anchor-5 territory with an EKM add-on as partial key custody. No end-to-end encryption, no device verification, no session management an admin can revoke, and no statement of what Slack cannot decrypt: an archive anyone at the vendor with the keys can read is not the one I want. 2 1 2 3

Report an error

The Works Council Advocate

Encryption at rest and in transit with vendor-held keys by default; Enterprise Key Management is only a paid add-on, which is the right direction but not first-class. SSO, 2FA, information barriers and admin control over DM visibility and external connections are documented, but there is no end-to-end mode and no plain statement of what Slack itself can read. 1 2 3 2

Report an error

The Compliance Counsel

Encryption at rest and in transit, SAML SSO, 2FA, SCIM, information barriers and EMM plus customer-controlled posting permissions, DM visibility and Slack Connect gating clear the anchor-5 bar, and the Enterprise Key Management add-on at least puts key handling on paper. But there is no end-to-end encryption anywhere in the evidence, no device verification or session revocation, and no plain statement of what the vendor itself can read. 2 3 2

Report an error

The Platform Engineer

Encryption at rest and in transit (vendor keys), SAML SSO down to the free tier, two-factor, information barriers and per-channel posting permissions — that's the 5 anchor. No end-to-end encryption mode, no device verification, no session revocation, and no statement of what Slack itself can read, so it cannot go higher. 2 3 2

Report an error

The Skeptic

Encryption at rest and in transit with the vendor holding the keys, plus SAML SSO down to Free, 2FA, information barriers and an Enterprise Key Management add-on — key custody you can rent, not E2EE. There is no end-to-end encryption and no sentence stating what the vendor itself can read anywhere in the evidence, and silence on that is the finding. 1 2 2

Report an error

Retention, discovery & co-determination

Show reasoning
How this is scored

The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.

0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.

3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.

5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.

8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.

10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.

Report an error

The Team Lead

Retention configurable at workspace and channel level (plan-dependent), plus legal hold, audit logs, DLP and information barriers on the pricing page — the legal object is at least named. Missing: eDiscovery export including edits and deletions, evidenced policy execution, and any word on whether activity analytics can be switched off organisation-wide, which is exactly what a works council asks first. 3 2

Report an error

The Security Officer

Retention configurable at workspace, channel or other level, legal hold and audit logs named, DLP on every plan — good bones for a legal object. But the evidence never evidences a discovery export format, capture of edits and deletions, or any switch for activity analytics, so I cannot certify the subpoena half of anchor-8. 3 2 2

Report an error

The Works Council Advocate

Retention is configurable at workspace and channel level, and legal hold, audit logs and native DLP exist — but the evidence is silent on discovery export in any format, on whether deletion is evidenced, on user-controlled presence, and on switching analytics off organisation-wide. A works agreement cannot rest on half of rubric level 5; those absences are information. 2 3

Report an error

The Compliance Counsel

Retention configurable at workspace and channel level, plus audit logs and a named legal-hold feature, carry this past rubric level 3. What the evidence never evidences is exactly what I would be subpoenaed for: an eDiscovery export including edits and deletions, proof that retention deletions are actually executed, and any organisation-wide switch for activity analytics — named bullets on a pricing page are not a discovery process. 2 3

Report an error

The Platform Engineer

Retention configurable at workspace, channel and other levels, audit logs, legal hold and native DLP are all evidenced — most of the 8-anchor list. But the evidence is silent on any export format a lawyer could use, on retention deletion being evidenced, and on whether activity analytics can be switched off, which caps it below 8. 2 3

Report an error

The Skeptic

Retention configurable at workspace and channel level (plan-dependent), legal hold, audit logs and native DLP on every plan — real governance bones. But no discovery or export format is documented in any form, and nothing says whether presence or activity analytics can be switched off — the archive as a legal object is half-built in this evidence. 2 3 2

Report an error

Deployment & data custody

Show reasoning
How this is scored

Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.

0 — Cloud-only, proprietary, with export limited to a partial archive.

3 — Cloud-only, but with a documented full export in an open-ish format.

5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.

8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.

10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.

Report an error

The Team Lead

Cloud-only from a proprietary San Francisco vendor: no self-hosting, no open-source core, no documented export format anywhere in the evidence. The only custody-adjacent facts are Germany hosting from Business+ and Slack hosting its own LLMs in its own AWS private cloud — neither puts my archive in my hands. 2 2

Report an error

The Security Officer

Cloud-only and proprietary, from a San Francisco vendor; the evidence documents no self-hosting, no federation and no archive export format at all — the only data-getting-out rights are GDPR access requests. Custody of the archive never leaves the vendor, and an exit path is entirely unevidenced, which is close to the anchor-0 floor. 3 1

Report an error

The Works Council Advocate

Cloud-only and proprietary: no self-hosting, no open source, no federation, and no documented full export anywhere in the evidence — not even the partial one rubric level 0 would still allow scoring. Germany data location from Business+ and LLMs in Slack's own AWS cloud are residency, not custody; the archive belongs to Salesforce either way. 2 2

Report an error

The Compliance Counsel

Nothing in the evidence offers the customer custody: no self-hosting, no private instance, no open source, and — decisive for an exit — no documented export of any kind. The EKM add-on and Germany hosting from Business+ are controls over Slack's cloud, not an alternative to it, so this sits at the bottom of the scale nudged up only by key custody. 2 2

Report an error

The Platform Engineer

Cloud-only and proprietary: no self-hosted edition, no open-source core, no federation — Slack Connect is a feature of their cloud, not an exit. The closest things to custody are the Enterprise Key Management add-on and a Germany data-location option, neither of which hands the customer the archive, and the evidence documents no full export format at all. 1 2 2

Report an error

The Skeptic

Cloud-only SaaS: the entire registry is tier pricing, and the one 'private cloud' sentence is Slack's own AWS private cloud for their LLMs, not a customer deployment option. No self-hosting, no open-source core, and no export path documented at all — even the anchor-3 bar of a documented full export goes unevidenced, and Germany residency from Business+ changes where the vendor holds your archive, not who holds it. 2 2

Report an error

Integrations & extensibility

panel disagrees Show reasoning
How this is scored

Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.

0 — No API, no webhooks, no bots.

3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.

5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.

8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.

10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.

Report an error

The Team Lead

An average of 43 apps per team and 1.7M weekly active apps say the ecosystem is real, automations are buildable 'with a click or by code', third-party services are controllable per workspace, and SCIM provisioning exists. 1 2 3

Report an error

The Security Officer

A genuine platform: buildable solutions by click or code, 1.7 million weekly active apps with named native integrations, SCIM provisioning, SSO, and workspace-level control over third-party services. Rate limits, a sandbox, API versioning and auditable app permissions are unevidenced, which keeps it below anchor-8. 1 2 3 2

Report an error

The Works Council Advocate

SSO, SCIM provisioning, a workflow builder usable with or without code, and named integrations (Google Drive, ChatGPT, Asana, Workday) with workspace-level allow/restrict control are all evidenced. But the evidence captures no documented API, no webhook model, no rate limits or sandbox — I cannot credit a platform on integration logos alone. 1 2 3

Report an error

The Compliance Counsel

A real ecosystem is implied — named integrations, SCIM provisioning, SAML SSO — and I welcome the workspace-level power to allow or restrict third-party services. But the evidence documents no REST API, no webhooks, no bot framework and no rate limits, so whether this is buildable without a partner agreement is unproven from evidence. 1 2 3 2

Report an error

The Platform Engineer

A real platform: a flexible build-your-own foundation, workflows by click or code, vendor-named integrations, SCIM provisioning, and workspace-level allow/restrict control over third-party services. What keeps it off 10 is the absence of a documented versioned API with deprecation policy, rate limits, and a sandbox in the evidence. 1 2 3

Report an error

The Skeptic

Named integrations, 1.7 million weekly active apps, automation 'mit einem Klick oder per Code', SCIM provisioning, SSO, and per-workspace control over third-party services. What's missing for the next anchor: any documented API surface, rate limits, sandbox or deprecation policy — this sheet evidences an ecosystem, not a documented platform. 1 2 3 2

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.

3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.

Report an error

The Team Lead

Salesforce, Inc. of San Francisco is the vendor and contracting entity, Germany data residency exists but only from Business+ upward, and no subprocessor list is published — the classic 'EU residency offered while the entity sits outside the EU' position. The LLM stack staying inside Slack's AWS private cloud is a nice touch but it's still Slack's cloud, not mine. 2 2

Report an error

The Security Officer

Germany data residency exists but only as an upsell from Business+, the contracting entity is US-based Salesforce, the LLM processing sits in a Slack AWS private cloud with no region named, and the subprocessor list is unpublished — that is precisely the anchor-3 shape: content residency offered while the rest of the chain stays opaque and non-EU. 2 2 3

Report an error

The Works Council Advocate

Germany data residency exists but only from Business+ upward, while the contracting entity is Salesforce, Inc. of San Francisco and the subprocessor chain is unnamed — exactly the rubric level 3 situation. The LLMs run in Slack's own AWS private cloud and ChatGPT is a showcased integration with no legal basis or safeguard stated for that reach. 1 2 2

Report an error

The Compliance Counsel

The contracting entity is Salesforce, Inc. of San Francisco and no subprocessor chain is named, while the AI stack runs in Slack's own AWS private cloud with no region stated and a US LLM provider sits in the integration list. Germany data residency exists but is purchasable only from Business+ upward — partial residency on top of a non-EU entity is precisely the anchor-3 pattern. 1 2 2

Report an error

The Platform Engineer

Salesforce Inc. of San Francisco is the vendor and contracting entity, subprocessors are unnamed in the evidence, and EU residency is a Germany checkbox that only starts at Business+ — the anchor-3 case exactly. The LLM stack runs in Slack's own AWS private cloud with no EU claim, and there is no self-hosted option that would remove the question. 2 2

Report an error

The Skeptic

The vendor is Salesforce, Inc. of San Francisco, and the pipeline could confirm neither contracting entity, ownership, default residency nor a single subprocessor on the captured pages. The one European fact — 'Datenstandort Deutschland' — starts at Business+, making EU custody an upsell, and the LLMs sit in Slack's AWS private cloud of unstated region. 2 2

Report an error

Pricing transparency

panel disagrees Show reasoning
How this is scored

Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.

5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.

8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.

10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.

Report an error

The Team Lead

Tier boundaries are unusually legible — SSO down to the free plan, unlimited history from Pro, Germany residency from Business+, DLP on every tier — and VAT-compliant invoices are a product feature. But no per-user figure is captured in this evidence and the compliance tier (legal hold, SCIM, audit) sits in Enterprise+ without a stated price, so I cannot compute my annual invoice from these pages alone. 2 2

Report an error

The Security Officer

The tier map is documented — SSO on every plan including free, Germany residency from Business+, unlimited history from Pro — but not one per-user price, billing period, VAT treatment or Enterprise Key Management add-on price appears in the evidence. A buyer can see which tier they need but cannot compute the annual invoice, and retention controls are explicitly plan-dependent with Enterprise+ pricing absent. 2 2 3

Report an error

The Works Council Advocate

Tier boundaries are genuinely public — which plan gets unlimited history, legal hold, audit logs, SCIM, Germany hosting and which SLA — and VAT-compliant invoices are downloadable. But not a single per-user price figure appears in the captured pricing pages, and Enterprise Key Management is an unpriced add-on, so the annual invoice for our headcount is not computable from what is published here. 2 2

Report an error

The Compliance Counsel

The pricing page does place compliance features per plan — DLP across plans, Germany residency from Business+, audit logs and legal hold listed, VAT-compliant invoices downloadable. But Enterprise Key Management is an unpriced add-on, the evidence shows no per-user figures or minimum term, and I cannot tell which tier legal hold actually sits in, so the annual invoice for my compliance setup is not computable from what is captured. 2 2

Report an error

The Platform Engineer

The pricing pages do map real feature boundaries — unlimited history from Pro, SSO from free, DLP on all plans, Germany hosting from Business+, SLA response times per tier — and VAT-compliant invoices are documented. But not one per-user price figure appears in the evidence and Enterprise+ remains unpriced, so the annual invoice is not computable from this sheet. 2 2

Report an error

The Skeptic

The tier boundaries are unusually legible — unlimited history from Pro, SAML SSO from Free, DLP on all plans, Germany residency from Business+, EKM as an add-on — but the registry contains not a single per-user price, billing period or VAT treatment. Without a number anywhere, the annual invoice is not computable from this evidence, so I score below the 'headline exists' anchor despite the good feature-to-tier mapping. 2 2

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined ⚠ unverified — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (12)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage slack.com Checked 15 Sep 2026 Details →
  2. 2 Pricing slack.com Checked 15 Sep 2026 +1 earlier capture: 15 Sep 2026 Details →
  3. 3 Privacy policy slack.com Checked 15 Sep 2026 Details →
  4. 4 Legal notice slack.com Checked 21 Sep 2026 Details →
  5. 5 Channels, threads & search — found from sitemap slack.com Checked 1 Oct 2026 Details →
  6. 6 Channels, threads & search — found from sitemap slack.com Checked 1 Oct 2026 Details →
  7. 7 Encryption & access control — found from sitemap slack.com Checked 1 Oct 2026 Details →
  8. 8 Encryption & access control — found from sitemap slack.com Checked 1 Oct 2026 Details →
  9. 9 Retention, discovery & co-determination — found from sitemap slack.com Checked 1 Oct 2026 Details →
  10. 10 Retention, discovery & co-determination — found from sitemap slack.com Checked 1 Oct 2026 Details →
  11. 11 Integrations & extensibility — found from sitemap slack.com Checked 1 Oct 2026 Details →
  12. 12 Integrations & extensibility — found from sitemap slack.com Checked 1 Oct 2026 Details →