Cookie Jar

Frequently asked questions

Quick answers about the product and how we handle your data.

Product

The questions we actually get.

trust & security

Built on industry-standard practices —
not bolted on later.

  • Encryption
    TLS in transit, AES-256 at rest. Slack bot tokens are encrypted with rotation support.
  • Signed webhooks
    Every request from Slack is verified with HMAC-SHA256 and a 5-minute replay window before we trust it.
  • Workspace isolation
    Your data is enforced-isolated at the database layer. Admins only see their own org.
  • Role-based access
    Every admin operation checks the operator's role on the workspace, every time.
  • Rate limiting
    Public endpoints are rate-limited to prevent abuse.
  • Audit log on every action
    Grant, revoke, approve, deny, admin promotion. Recorded with actor, target, tool, and timestamp.
  • OAuth installer gate
    Only Slack workspace admins or owners can install Cookie Jar — preventing employees from auto-promoting themselves.
honest
Compliance status
Cookie Jar is not yet SOC 2 certified. We follow the practices that lead there and will pursue formal certification as customers require it. We don't make claims we can't back up.

Security questions buyers actually ask

Still considering Cookie Jar?