Skip to main content

Secure Customer Service

Cover your bases

Zendesk takes security very seriously—just ask the number of Fortune 100 and Fortune 500 companies that trust us with their data. We use a combination of enterprise-class security features and comprehensive audits of our applications, systems, and networks to ensure that your data is protected, which means every customer can rest easy—our own included.

Global Standards, Independently Verified

Zendesk aligns with the world’s most rigorous security and privacy frameworks. We don't just follow best practices; we undergo continuous independent auditing to ensure our controls meet the highest standards. This rigorous validation simplifies your own vendor risk assessments and helps you meet your compliance obligations with confidence.

Learn more

SOC 2 Type II

We undergo routine audits to receive updated SOC 2 Type II reports, available upon request and under NDA. Request the latest SOC 2 Type II report.

ISO 27001:2022

Zendesk is ISO 27001:2022 certified. Download the certificate.

ISO 27018:2019

Zendesk is ISO 27018:2019 certified. The certificate is available for download here.

ISO 27701:2019

Zendesk is ISO 27701:2019 certified. The certificate is available for download here.

ISO 27017:2015

Zendesk is ISO 27017:2015 certified. The certificate is available for download here.

ISO 42001

ISO 42001 is the world’s first international standard for managing artificial intelligence. Achieving certification means that Zendesk’s AI practices — spanning design and development through deployment and ongoing monitoring — have been independently audited for conformance with a formal Artificial Intelligence Management System (AIMS) and demonstrate transparency, security, and responsible governance.

FedRAMP LI-SaaS

Zendesk is FedRAMP authorized with Low Impact Software-as-a-Service (LI-SaaS) and is listed in the FedRAMP Marketplace. US Government agency subscribers can request access to the Zendesk FedRAMP Security Package by completing a Package Access Request Form or submitting a request to fedramp@zendesk.com.

Cyber Essentials Plus

Cyber Essentials Plus is a UK government-backed certification that demonstrates an organization’s commitment to strong cybersecurity through independent verification of key controls.

CSA STAR AI Levels 1 & 2

CSA STAR AI Levels 1 & 2 certify advanced cloud security and AI governance practices, with Zendesk proudly being the first in the industry to achieve this recognition.

Security Artifacts & Due Diligence

Accelerate your vendor review. Gain instant, self-serve access to our comprehensive library of security documentation. Log in to the Trust Portal to download current certifications, audit reports, policy documents, and standardized security questionnaires.

SOC 2 Type II

Our security controls are audited annually against the AICPA Trust Services Criteria. Our Type II report covers Security, Availability, and Confidentiality, demonstrating the operating effectiveness of our controls over time.

ISO Certification Suite

Zendesk maintains a comprehensive Integrated Management System (IMS) audited against key ISO standards.

  • ISO 27001:2022: Information Security Management
  • ISO 27017:2015: Cloud Security
  • ISO 27018:2019: Privacy & PII Protection in the Cloud
  • ISO 27701:2019: Privacy Information Management
  • ISO 42001:2023: AI Management System

Cloud Security

We host Service Data primarily in Amazon Web Services (AWS) data centers that are certified as ISO 27001, PCI DSS Service Provider Level 1, and SOC 2 compliant.

Global Reach

We leverage data centers in the United States, Europe (EEA), and Asia Pacific.

Data Locality

You can choose where your data resides based on your region.

Physical Security

AWS data centers employ 24/7 surveillance, biometric access, and strict personnel controls.

Vendor Risk Management

We continuously safeguard our supply chain. Any third-party vendor with potential access to our systems or Service Data must undergo a rigorous security and privacy risk assessment prior to onboarding, followed by regular lifecycle reviews to ensure ongoing adherence to our strict standards.

Incident Response Readiness

Our 24/7 globally distributed Security, Network Engineering, and Operations teams adhere to a mature, continuously tested Incident Response Plan. In the event of an anomaly, established escalation protocols ensure rapid containment, remediation, and transparent communication.

Product & People Security

Security is integrated into every stage of our development process.

Training

All engineers receive annual secure code training based on OWASP Top 10 risks.

Automated Scanning

We use Static (SAST) and Dynamic (DAST) analysis tools to identify vulnerabilities in code and dependencies (SCA) before deployment.

Separate Environments

Development, testing, and staging environments are logically separated from production data.

Welcome to the Zendesk Global Privacy Program

Zendesk has a formal global privacy and data protection program, which includes cross-functional key stakeholders including Legal, Security, Product, and Executive sectors of the company. As privacy advocates, we work diligently to ensure our Services and team members are dedicated to compliance with applicable regulatory and industry frameworks.

The Australian Privacy Act of 1988 (as amended) provides several data subject rights and added mandatory notification of eligible data breaches. Unlike the GDPR, there are no concepts of data controller and data processor. https://www.zendesk.com/company/anz-privacy/

Subscriber Service Data Details

Service Data is any information, including personal data, which is stored in or transmitted via the Zendesk Services by, or on behalf of, our subscribers and their end-users. We use Service Data to operate and improve our Services, help customers access and use the Services, respond to subscriber inquiries, and send communications related to the Services.

Access: Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services and as otherwise required by law. See here for additional information.

Data Hosting: Zendesk uses Amazon Web Services to host Service Data as described here and in the Regional Data Hosting Policy. For additional information, please also see the Security section.

Default Data Types Collected by the Service: Zendesk has created a list of data points, categorized by product. For the full picture of data types, subscribers can use this list in conjunction with their specific intended use case and resultant data types.

Legal or Government Requests: Privacy, data security, and subscriber trust are our top priorities. Zendesk does not disclose Service Data, except as necessary to provide our Services and to comply with applicable laws, as detailed in our Privacy Notice. To assist our subscribers in performing compliance reviews, we have additional resources: Transparency Report and Government Request Policy.

Ownership: From a privacy perspective, the subscriber is the controller of Service Data and Zendesk is a processor. This means that throughout the time that you subscribe to services with Zendesk, you retain ownership of and control over Service Data in your Zendesk instance.

Replication: Zendesk periodically replicates data for purposes of archival, backup, and audit logs. We use Amazon Web Services (AWS) to store some of the information that is backed up, such as database information and attachment files. Please see our Regional Data Hosting Policy for further details.

Security: Zendesk prioritizes data security and combines enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure subscriber and business data is protected. See additional information here.

Security Incidents: For more information about security incident management see our Security Incident Response.

Sub-processors: Zendesk may use sub-processors, including affiliates of Zendesk, as well as third-party companies, to provide, secure, or improve the Services, and such sub-processors may have access to Service Data. Our Sub-processors policy provides an up-to-date list of the names and locations of all sub-processors.

Termination: Zendesk maintains a Service Data Deletion Policy that describes Zendesk’s data deletion processes upon subscriber’s termination or expiration of the Zendesk subscription.

Privacy Related Policies

Cookie Policy

Detailed information about how and when we use cookies on Zendesk websites.

In-Product Cookie Policy

Provides information about how and when Zendesk uses cookies within the Zendesk Services.

Service Data Deletion Policy

How our Subscribers’ Service Data is deleted in connection with the cancellation, termination, or migration of an Account within the Zendesk Services.

Shared Responsibility Model

This framework clarifies which party is responsible for which controls related to the security and privacy of your data.

Application Features Related to Privacy

Zendesk has tools for each of its products to assist with user requests and other obligations under applicable privacy and data protection laws and regulations, such as data access, correction, portability, deletion, and objection. To learn about the features and functionality in each Zendesk product, please see Complying with Privacy and Data Protection in Zendesk products.

Zendesk AI

Zendesk AI is built based on the core principles of privacy, security, and compliance, by design. Our commitment to providing businesses with secure, trusted products and solutions is embedded in our DNA. As part of this, Zendesk leverages a set of design principles that not only set the standard for how we design, develop, and build everything we do, but set a clear foundation for our use of AI for customer experiences (CX and employee experience (EX)). For more information, see AI Trust at Zendesk.

Service Data processed by Zendesk AI is subject to all security standards and commitments, including compliance with Zendesk’s robust Enterprise Security Measures, and storage within Zendesk’s SOC 2-compliant environment. Service Data will not be shared with any other customer.

Generative AI features are currently powered by OpenAI (using zero data retention endpoints) or models hosted on Microsoft Azure, Amazon Bedrock, or Google Cloud Platform (where the model provider never has access to prompts or outputs). We also offer AI transcription services powered by Twilio and DeepGram.

OpenAI data security practices are available here. Amazon Bedrock data security practices are available here. Microsoft Azure data security practices are available here. Google Cloud Platform data security practices are available here.

This could be the beginning of a beautiful relationship