Security

Built for teams that have to ask the hard questions

Everything an admin needs to review before rolling Super Duper out — access scope, retention, deletion, encryption, and who processes your data.

What the bot can — and can’t — see

Super Duper only reads channels it has been invited to and conversations it is part of. It cannot browse your workspace or read other people’s DMs. See the full permissions breakdown →

No training on your data

We do not use your workspace content to train third-party foundation models. Your messages and files are used to answer your requests — not to train models for others.

Retention

We retain data while your account and installation are active. Removing Super Duper from Slack stops further processing. Some records may be kept where required for legal, accounting, or security purposes.

Deletion

Delete your account from Settings at any time to remove your associated profile data. Uninstalling from Slack immediately revokes the bot’s access to your workspace.

Token storage

Third-party access tokens (Slack and any tools you connect) are encrypted at rest. Card details are handled by Stripe — we never store full card numbers.

Encryption & access control

Data is encrypted in transit. Access to production systems is scoped and controlled, and the bot’s reach is limited to the channels and tools you explicitly grant.

Subprocessors

We share data only with the providers that help us run the service, each under contract.

SupabaseDatabase & authentication
Amazon Web ServicesCloud infrastructure & AI model hosting (Bedrock)
AnthropicAI model processing (via Amazon Bedrock)
VercelApplication hosting
StripePayments & billing
BraintrustQuality evaluation & observability of AI interactions
PipedreamConnecting third-party sources you choose to add

Security contact

Reporting a vulnerability or have a security question? We respond within 2 business days.

support@superduper.website

Confident it’s a fit? Bring it to your team.

Free to try · No credit card