Hey folks. New Vector (the Element vendor) completed the encryption tool they told us they would develop in the hope that we could use it to bridge our private Slack channels and DMs to Element. As a reminder, Legal, ITS, and Security agreed to only bridge "public" Slack channels (public in the sense that anyone in our Slack workspace can join these channels) to our Matrix server until New Vector developed a bridge encryption tool that satisfied our security needs. Below is the information New Vector shared with me.
The basics of the tool are explained in the bridge's documentation at Bridge Encryption
The code is open-source and mainly contained in these projects:
matrix-appservice-slack – The Matrix <-> Slack bridge
matrix-appservice-bridge – A foundational library for most Matrix bridges.
pantalaimon – An encryption-aware proxy daemon for Matrix clients.
Do you need any additional information to complete an audit of their data encryption solution and determine whether it satisfies our security needs? Would you like me to set up a meeting with the vendor to discuss this tool?
Thank you!