Security at Nimbus
Nimbus lives inside your Slack workspace and executes real tasks on your behalf. Here is exactly how we protect your data, limit our access, and earn your trust.
Access Model
What Nimbus can see
Nimbus reads messages in channels where it is explicitly mentioned or invited. It does not passively monitor your Slack workspace. It cannot read threads it was not part of, direct messages between other users, or channels it has not been added to. Access is scoped per workspace — one tenant's Nimbus never interacts with another tenant's Slack.
OAuth scopes
We request only the Slack scopes required to function: app_mentions:read, chat:write, channels:history, im:read, im:write. We do not request admin scopes, file read access, or user data beyond what is needed to respond to your messages.
Revoking access
You can revoke Nimbus's access at any time from your Slack workspace settings under Manage Apps. Revocation is immediate. We will delete your workspace's stored memory and configuration within 7 days of a written deletion request to support@nimbus.fan.
Data Storage & Retention
What we store
Nimbus stores a rolling memory of your interactions — summaries of tasks completed, preferences learned, and facts about your business that help it do better work over time. This is stored on an isolated volume attached to your dedicated cloud container. No other tenant's Nimbus has access to your volume.
Message content
Raw message text is not stored long-term. Nimbus processes messages in memory to produce a response, then discards the raw content. What persists is extracted knowledge (e.g. "prefers responses under 200 words", "uses Notion for project tracking"), not verbatim transcripts.
Retention periods
Memory is retained for the duration of your subscription. On cancellation, memory is retained for 30 days to allow re-activation, then permanently deleted. The $499 Nimbus Operator plan includes the standard workspace memory window. Custom retention can be handled by agreement.
Data residency
All infrastructure runs on Fly.io, with machines deployed in US-East (Ashburn, VA) by default. Customers can request EU or alternative region placement.
Infrastructure & Isolation
Dedicated containers
Every Nimbus workspace runs in its own isolated container on Fly.io — a separate machine with its own CPU, memory, and encrypted volume. There is no shared compute between tenants. A security issue in one tenant's container cannot affect another.
Encryption
Data at rest is encrypted using AES-256 via Fly.io's managed volume encryption. Data in transit is encrypted via TLS 1.3 across all connections — Slack to Nimbus, Nimbus to external services, and Nimbus to our internal infrastructure.
Credentials
Your Slack OAuth token is stored encrypted on your tenant's isolated volume and served only to your container. Tokens are never logged, never transmitted externally, and never shared across tenants. Token rotation is handled automatically every 4 hours.
No persistent internet exposure
Nimbus containers communicate with Slack via WebSocket (outbound) — there is no inbound HTTP port exposed to the public internet on tenant machines. Event routing happens via Fly.io's private internal network.
AI Model Usage
Which models we use
Nimbus can route work across approved model providers, including Anthropic, OpenAI, and Google, depending on the tenant configuration and task type. Model selection is controlled by Nimbus and can be changed without changing the Slack interface customers use.
Your data and model training
Nimbus does not share customer workspace content with model providers for training. Customer data is sent only as needed to complete the requested task under the configured commercial provider path.
What is sent to the model
Each task invocation sends: the current message, relevant memory snippets, and workspace context (your CLAUDE.md configuration). No raw historical Slack messages are sent unless they are directly relevant to the active task.
Compliance & Certifications
SOC 2
SOC 2 Type II certification is in progress. Target completion: Q3 2026. Customers customers can request our current security controls summary and penetration test results in advance of formal certification.
GDPR
Nimbus complies with GDPR for EU-based customers. We act as a Data Processor under Article 28 when handling personal data on your behalf. A Data Processing Agreement (DPA) is available upon request for customers.
CCPA
Nimbus does not sell personal data. CCPA rights (access, deletion, portability) can be exercised by contacting support@nimbus.fan.
Slack App Directory
Nimbus is pending Slack App Directory review. All Slack API usage conforms to Slack's Platform Terms of Service and Developer Policy.
Incident Response
Disclosure policy
In the event of a security incident that affects customer data, we will notify affected workspace administrators within 72 hours of discovery — consistent with GDPR Article 33 timelines. Notification will include: what happened, what data was affected, what we have done, and what you should do.
Vulnerability reports
If you discover a security vulnerability, please report it to support@nimbus.fan. We investigate all reports within 2 business days and follow responsible disclosure principles. We do not pursue legal action against good-faith security researchers.
Questions about security?
Customers can request our full security package — controls summary, DPA, and infrastructure diagrams.
This page reflects Nimbus's security posture as of March 2026. It is reviewed quarterly.