Discord data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Discord, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Discord connector needs.
Checks (8)
severity: medium Content Filter Not Full fix difficulty: easy #
Set the explicit content filter to scan messages from all members
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Safety Setup" in the left panel
- Under "Explicit Image Filter", select "Scan content from all members"
- Save the changes
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Guild Publicly Discoverable fix difficulty: easy #
Disable Server Discovery to prevent the server from being publicly listed
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Discovery" in the left panel
- Disable the "Enable Server Discovery" toggle
- Confirm and save the changes
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: low Widget Enabled fix difficulty: easy #
Disable the server widget to prevent public exposure of member count and invite link
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Widget" in the left panel
- Toggle off "Enable Server Widget"
- Save the changes
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high No AutoMod Rules fix difficulty: medium #
Enable AutoMod rules to protect the server against spam, harmful content, and mention abuse
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "AutoMod" in the left panel
- Click "Create Rule" and configure at least one rule (e.g. keyword filtering or mention spam)
- Set appropriate actions such as blocking the message or timing out the member
- Enable and save the rule
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium No Keyword Filtering fix difficulty: medium #
Enable AutoMod keyword filtering to block messages containing harmful or prohibited words
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "AutoMod" in the left panel
- Click "Create Rule" and select "Block Custom Words"
- Add your list of prohibited keywords or phrases
- Configure the block action and optionally add exempt roles or channels, then save
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium No Spam Protection fix difficulty: medium #
Enable AutoMod spam protection to automatically detect and block spam messages
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "AutoMod" in the left panel
- Click "Create Rule" and select "Block Spam Content"
- Choose the action to take on detection (block message, timeout member)
- Optionally configure exempt roles or channels, then enable and save the rule
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: low No Mention Spam Protection fix difficulty: easy #
Enable AutoMod mention spam protection to prevent mass-mention abuse
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "AutoMod" in the left panel
- Click "Create Rule" and select "Block Mention Spam"
- Set the maximum number of unique mentions allowed per message
- Enable the rule and save
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: info NSFW Channel fix difficulty: easy #
Review NSFW channel designations and ensure age-restricted channels are intentional
- Open Discord and locate the flagged channel in the channel list
- Right-click the channel and select "Edit Channel"
- Navigate to the "Overview" tab
- Review whether the "Age-Restricted Channel" toggle is intentionally enabled
- If the channel should not be age-restricted, disable the toggle and save
- Document approved NSFW channels and enforce a governance policy for future additions
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11