Skip to content

Discord data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Discord, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Discord connector needs.

Checks (8)

severity: medium Content Filter Not Full fix difficulty: easy #

Set the explicit content filter to scan messages from all members

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "Safety Setup" in the left panel
  4. Under "Explicit Image Filter", select "Scan content from all members"
  5. Save the changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Guild Publicly Discoverable fix difficulty: easy #

Disable Server Discovery to prevent the server from being publicly listed

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "Discovery" in the left panel
  4. Disable the "Enable Server Discovery" toggle
  5. Confirm and save the changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: low Widget Enabled fix difficulty: easy #

Disable the server widget to prevent public exposure of member count and invite link

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "Widget" in the left panel
  4. Toggle off "Enable Server Widget"
  5. Save the changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high No AutoMod Rules fix difficulty: medium #

Enable AutoMod rules to protect the server against spam, harmful content, and mention abuse

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "AutoMod" in the left panel
  4. Click "Create Rule" and configure at least one rule (e.g. keyword filtering or mention spam)
  5. Set appropriate actions such as blocking the message or timing out the member
  6. Enable and save the rule

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium No Keyword Filtering fix difficulty: medium #

Enable AutoMod keyword filtering to block messages containing harmful or prohibited words

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "AutoMod" in the left panel
  4. Click "Create Rule" and select "Block Custom Words"
  5. Add your list of prohibited keywords or phrases
  6. Configure the block action and optionally add exempt roles or channels, then save

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium No Spam Protection fix difficulty: medium #

Enable AutoMod spam protection to automatically detect and block spam messages

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "AutoMod" in the left panel
  4. Click "Create Rule" and select "Block Spam Content"
  5. Choose the action to take on detection (block message, timeout member)
  6. Optionally configure exempt roles or channels, then enable and save the rule

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: low No Mention Spam Protection fix difficulty: easy #

Enable AutoMod mention spam protection to prevent mass-mention abuse

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "AutoMod" in the left panel
  4. Click "Create Rule" and select "Block Mention Spam"
  5. Set the maximum number of unique mentions allowed per message
  6. Enable the rule and save

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: info NSFW Channel fix difficulty: easy #

Review NSFW channel designations and ensure age-restricted channels are intentional

  1. Open Discord and locate the flagged channel in the channel list
  2. Right-click the channel and select "Edit Channel"
  3. Navigate to the "Overview" tab
  4. Review whether the "Age-Restricted Channel" toggle is intentionally enabled
  5. If the channel should not be age-restricted, disable the toggle and save
  6. Document approved NSFW channels and enforce a governance policy for future additions

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

More Discord checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial