Encrypted in transit
Data moving between Slack, Luffy, and our infrastructure is protected with TLS.
Security at Luffy
Security is core to how Luffy operates inside your Slack workspace. We protect your data across infrastructure, access, and every action Luffy takes on your behalf.
01 · Data protection
Luffy applies the same core safeguards whether you are asking a question in Slack or authorizing work in a connected tool.
Data moving between Slack, Luffy, and our infrastructure is protected with TLS.
Stored application data and credentials are encrypted while at rest.
Each Slack workspace is scoped independently. One workspace's data is never visible to another.
Every action is tied to the Slack user who requested it and their approved access.
02 · Infrastructure and subprocessors
We use a focused set of providers to operate Luffy reliably and securely.
We do not sell workspace data to third parties.
We do not use Slack conversation data to train large language models.
See our privacy policy for more about data use and retention.
03 · Access controls
Slack OAuth scopes are limited to the features Luffy actually uses. The full scope list explains why each permission is needed.
Production access is limited to the engineers who need it, with permissions kept as narrow as possible.
Luffy checks the requester and workspace context before it uses an approved tool or takes an action.
Runs retain operational metadata such as request ID, timestamp, status, and tool used for review and troubleshooting.
04 · Compliance
Luffy is actively progressing through independent security reviews and compliance readiness work.
SOC 2 audit preparation and evidence collection are underway.
CASA Tier 2 assessment of our Google Workspace integration is underway.
Slack's app directory review is underway.
05 · Incident response
If you discover a security issue or vulnerability, let us know. We will acknowledge the report and investigate promptly.
Still have a question?
We are happy to help with security reviews and product questions.