Cookie Jar
Frequently asked questions
Quick answers about the product and how we handle your data.
Product
The questions we actually get.
trust & security
Built on industry-standard practices —
not bolted on later.
- ✓EncryptionTLS in transit, AES-256 at rest. Slack bot tokens are encrypted with rotation support.
- ✓Signed webhooksEvery request from Slack is verified with HMAC-SHA256 and a 5-minute replay window before we trust it.
- ✓Workspace isolationYour data is enforced-isolated at the database layer. Admins only see their own org.
- ✓Role-based accessEvery admin operation checks the operator's role on the workspace, every time.
- ✓Rate limitingPublic endpoints are rate-limited to prevent abuse.
- ✓Audit log on every actionGrant, revoke, approve, deny, admin promotion. Recorded with actor, target, tool, and timestamp.
- ✓OAuth installer gateOnly Slack workspace admins or owners can install Cookie Jar — preventing employees from auto-promoting themselves.
honest
Compliance status
Cookie Jar is not yet SOC 2 certified. We follow the practices that lead there and will pursue formal certification as customers require it. We don't make claims we can't back up.
Security questions buyers actually ask
Still considering Cookie Jar?