Secure team scheduling, company-wide: the security behind OneSlate Workspace
What OneSlate Workspace can do
The workspace features focus on removing the manual work that comes with team scheduling.
Group booking. With a single link, every member's calendar syncs instantly, and only the shared open slots are surfaced. No more comparing candidate dates by hand or going back and forth over email.
Cross-organization coordination. Coordinate with external members on different domains safely, with privacy intact. Even recurring meetings for projects that include partner companies can be arranged across organizational boundaries.
One person, multiple accounts. A single person can connect multiple calendar accounts — work and personal, Google and Microsoft — and OneSlate calculates true availability across all of them. No risk of double-booking.
Guests don't need an account. External guests simply pick an open time from a shared link. No sign-up required.
The question behind the convenience: "Is it safe to entrust?"
These features also mean that calendar information from multiple organizations is being combined into a single account. From an evaluator's standpoint, the questions follow naturally: Is the combined information kept separate? Could an external guest see the contents of an event? Are data in transit and at rest encrypted? What, beyond the calendar, can the tool access?
OneSlate is built to answer these questions from the design stage, not as an afterthought. Here are six perspectives.
Security by design — six pillars
1. Authentication and two-factor authentication
You can sign in with Google, Microsoft, or email. With Google and Microsoft sign-in, authentication is delegated to each provider, and OneSlate never holds your password. Passwords for the email method are encrypted and stored using industry-standard practices.
On top of that, whichever sign-in method you use, you can add two-factor authentication with an authenticator app (TOTP). Recovery codes are issued as well, so you're covered even if you lose your device.
2. Encrypted in transit and at rest
All communication is encrypted with TLS. Stored data is managed on an encrypted platform, and the connection keys (access tokens) to your external calendars are also encrypted. We never hold the keyring in plain text.
3. Least-privilege access
OneSlate requests only the permissions to view your calendar and create events. It never touches your email, contacts, or files. And this permission scope has passed Google's review — third-party verification means something different from self-declaration.
4. Data separated by organization
Data is isolated at the database level, per user (Row Level Security). Even when you combine the calendars of multiple organizations into a single account, others' data is structurally inaccessible. "Combined but never mixed" is guaranteed by the architecture, not by operational rules.
5. Public pages never reveal event details
A booking page shows only whether you're free or busy. The title, participants, and location of an event are never made public. Even when you've combined calendars from several organizations, the only thing that leaves the system is whether you're available.
6. Built on a trusted foundation
OneSlate runs on SOC 2-compliant cloud infrastructure. For enterprise evaluations, a more detailed security whitepaper is available on request.
In closing
Team scheduling becomes more valuable as more organizations get involved — and at the same time, the demands on how information is handled grow heavier. OneSlate Workspace was designed to meet both, giving security the same weight as convenience.
Even when you combine the calendars of multiple organizations into one, your data stays separated and encrypted by organization, and the contents of your schedule are never exposed externally. Use it with confidence, across your entire company.
Try OneSlate / Request the security whitepaper
</parameter> </invoke>