Yes
According to their white paper Slack uses TLS 1.2 to protect external data.
Yes
Slack meets the recommended cryptographic profiles for TLS as published by the NCSC. In addition the Slack domain currently gets an ‘A+’ rating from Qualys SSL Labs. Note that this was performed on their top level domain, and not all subdomains that may be used for API calls.
Unknown
Slack’s white paper only discusses data in transit on public networks or at rest.
Unknown
It is not known if Slack protects data in transit.
Yes
All API requests made to Slack need a valid OAuth token as described in the API documentation.
Yes
Yes
Does the SaaS provider collect logs of events?
Types of log may include security logs and resource logs
Yes
Yes
Does the SaaS provider have a clear incident response and patching system in place to remedy any publicly reported issues in their service, or libraries that the service makes use of?
The provider’s previous track record on this is a good metric to see how they’ll cope with a new issue occurring.
Yes
Source: NCSC