Independent attestation that our security controls operate as designed. Type II in progress.
Report available under NDA.
Built so your credentials never touch the AI, every sensitive action waits for approval, and your data never trains a model.
Get Started for FreeEmmanuel is published in the official Slack App Directory. That means our OAuth scopes, security posture, and store listing have been reviewed and approved by Slack before we were allowed to ship to customers through their store.
One-click install from inside Slack. No infra to provision. No long procurement detour just to start a pilot.
Compliance
The audit reports are real, the controls are continuously monitored, and the next audit is always on the calendar.
Independent attestation that our security controls operate as designed. Type II in progress.
Report available under NDA.
EU data protection requirements met.
DPA available on request.
California Consumer Privacy Act requirements met.
Privacy documentation available.
Cloud Application Security Assessment, the highest tier required for Google API access.
Attestation included in compliance pack.
OAuth scopes and security posture vetted before shipment through the Slack store.
Public App Directory listing.
ISMS controls implementation and evidence collection in progress.
Controls overview available today; audit evidence shared after certification.
Data handling
Here's exactly what Emmanuel touches — and what he never does.
TLS 1.2+ in transit. AES-256 at rest. Secrets in dedicated vaults.
SAML SSO across Okta (inside Slack), Entra ID, Google Workspace, OneLogin and any SAML 2.0 IdP.
US-hosted by default. EU data residency available on Enterprise contracts.
Admins can disconnect any integration, pause any user, or kill a running task in one click.
Your conversations and files never enter a training set — not ours, not our model providers'.
API keys and tokens are injected at execution time by the tool gateway; the model never sees them.
Money moves, code pushes, and customer emails wait for your explicit approval in Slack.
Skills, integrations, and memory are walled off per workspace. No cross-tenant access.
AI Safety

A backend tool gateway injects your API keys and OAuth tokens at execution time. The AI model itself never sees them.
Not a policy. The architecture.

Before Emmanuel sends an email, pushes code, modifies an ad campaign, or charges a card, he shows you exactly what he wants to do and waits for approval or rejection in Slack.
Admins choose which action types require approval. Defaults are conservative.

Conversations, files, business data, and outputs stay in your workspace. We do not use customer data to train Emmanuel, and our model providers do not either.
Enterprise customers can turn persistent memory off per workspace or channel.

Every workspace runs in a sandboxed execution environment with no cross-tenant access. Skills, integrations, and memory are walled off per workspace.
What happens in your Slack stays in your Slack.
Emmanuel vs AI tools
AI employees introduce attack surfaces traditional SaaS does not have. Three controls keep the surface small.
Untrusted content is rendered as data, not commands. Admins put high-risk tools behind human approval, so an injection can't trigger gated actions like moving money or pushing code on its own.
Inference runs on OpenAI, Anthropic, and Google. Each is on the public sub-processor list with a no-training agreement for Emmanuel traffic.
Memory is scoped to your workspace, encrypted at rest, never used to train models, and fully exportable or deletable on request.
Credentials & secrets
Every major tool connects via OAuth with the narrowest scopes that get the job done. No passwords stored.
Where API keys are required, they are stored in a secrets vault, AES-256 at rest, isolated from model context, access-logged, and rotatable.
Admins decide which integrations are connected, who can use them, and at what level. Revoke any integration in one click.

Responsible disclosure
We would rather hear about an issue from a researcher than read about it on Twitter.
Send security reportWe are building a formal bug bounty program. In the meantime, we recognize meaningful security research with a thank you, public credit if you want it, and Emmanuel credits.
No. Credentials are stored in encrypted vaults and injected at execution time by a backend tool gateway. The AI model never sees them in any context, including planning, execution, or logs.
No. We don't train Emmanuel on customer data. Our model providers don't either.
Sensitive actions like sending emails, pushing code, modifying campaigns, deploying apps, or charging cards require explicit human approval via Slack before Emmanuel executes. Admins choose which action types require approval. Defaults are conservative.
Every workspace runs in its own sandboxed execution environment with no cross-tenant data access at the infrastructure or application layer.
Start free. Pay only
when you're ready.
Every feature. Every integration. $100 in credits on the house. No credit card, no sales call, no catch. When you need more, it starts $50/month.