Security Artifacts & Due Diligence
Accelerate your vendor review. Gain instant, self-serve access to our comprehensive library of security documentation. Log in to the Trust Portal to download current certifications, audit reports, policy documents, and standardized security questionnaires.
SOC 2 Type II | Our security controls are audited annually against the AICPA Trust Services Criteria. Our Type II report covers Security, Availability, and Confidentiality, demonstrating the operating effectiveness of our controls over time. |
ISO Certification Suite | Zendesk maintains a comprehensive Integrated Management System (IMS) audited against key ISO standards.
|
Cloud Security
We host Service Data primarily in Amazon Web Services (AWS) data centers that are certified as ISO 27001, PCI DSS Service Provider Level 1, and SOC 2 compliant.
Global Reach | We leverage data centers in the United States, Europe (EEA), and Asia Pacific. |
Data Locality | You can choose where your data resides based on your region. |
Physical Security | AWS data centers employ 24/7 surveillance, biometric access, and strict personnel controls. |
Vendor Risk Management | We continuously safeguard our supply chain. Any third-party vendor with potential access to our systems or Service Data must undergo a rigorous security and privacy risk assessment prior to onboarding, followed by regular lifecycle reviews to ensure ongoing adherence to our strict standards. |
Incident Response Readiness | Our 24/7 globally distributed Security, Network Engineering, and Operations teams adhere to a mature, continuously tested Incident Response Plan. In the event of an anomaly, established escalation protocols ensure rapid containment, remediation, and transparent communication. |
Product & People Security
Security is integrated into every stage of our development process.
Training | All engineers receive annual secure code training based on OWASP Top 10 risks. |
Automated Scanning | We use Static (SAST) and Dynamic (DAST) analysis tools to identify vulnerabilities in code and dependencies (SCA) before deployment. |
Separate Environments | Development, testing, and staging environments are logically separated from production data. |
Subscriber Service Data Details
Service Data is any information, including personal data, which is stored in or transmitted via the Zendesk Services by, or on behalf of, our subscribers and their end-users. We use Service Data to operate and improve our Services, help customers access and use the Services, respond to subscriber inquiries, and send communications related to the Services.
Access: Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services and as otherwise required by law. See here for additional information.
Data Hosting: Zendesk uses Amazon Web Services to host Service Data as described here and in the Regional Data Hosting Policy. For additional information, please also see the Security section.
Default Data Types Collected by the Service: Zendesk has created a list of data points, categorized by product. For the full picture of data types, subscribers can use this list in conjunction with their specific intended use case and resultant data types.
Legal or Government Requests: Privacy, data security, and subscriber trust are our top priorities. Zendesk does not disclose Service Data, except as necessary to provide our Services and to comply with applicable laws, as detailed in our Privacy Notice. To assist our subscribers in performing compliance reviews, we have additional resources: Transparency Report and Government Request Policy.
Ownership: From a privacy perspective, the subscriber is the controller of Service Data and Zendesk is a processor. This means that throughout the time that you subscribe to services with Zendesk, you retain ownership of and control over Service Data in your Zendesk instance.
Replication: Zendesk periodically replicates data for purposes of archival, backup, and audit logs. We use Amazon Web Services (AWS) to store some of the information that is backed up, such as database information and attachment files. Please see our Regional Data Hosting Policy for further details.
Security: Zendesk prioritizes data security and combines enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure subscriber and business data is protected. See additional information here.
Security Incidents: For more information about security incident management see our Security Incident Response.
Sub-processors: Zendesk may use sub-processors, including affiliates of Zendesk, as well as third-party companies, to provide, secure, or improve the Services, and such sub-processors may have access to Service Data. Our Sub-processors policy provides an up-to-date list of the names and locations of all sub-processors.
Termination: Zendesk maintains a Service Data Deletion Policy that describes Zendesk’s data deletion processes upon subscriber’s termination or expiration of the Zendesk subscription.
Privacy Related Policies
| Cookie Policy | Detailed information about how and when we use cookies on Zendesk websites. |
| In-Product Cookie Policy | Provides information about how and when Zendesk uses cookies within the Zendesk Services. |
| Service Data Deletion Policy | How our Subscribers’ Service Data is deleted in connection with the cancellation, termination, or migration of an Account within the Zendesk Services. |
| Shared Responsibility Model | This framework clarifies which party is responsible for which controls related to the security and privacy of your data. |
Application Features Related to Privacy
Zendesk has tools for each of its products to assist with user requests and other obligations under applicable privacy and data protection laws and regulations, such as data access, correction, portability, deletion, and objection. To learn about the features and functionality in each Zendesk product, please see Complying with Privacy and Data Protection in Zendesk products.