VendorScore · Customer support · Data-access posture

Can Zendesk read your support tickets?

A plain-language answer from Zendesk's public Trust Center, Help Center and legal pages. Advanced encryption covers user fields; ticket conversations stay on Zendesk-managed keys.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, Zendesk can read your tickets by design (with controls). Its BYOK covers user identity fields, not ticket content, and Zendesk trains cross-account classification models on Service Data. Support can only enter your account if an admin enables account assumption.

55 / 100 overall

Scored configuration: Zendesk Suite Enterprise with the Advanced Data Privacy and Protection (ADPP) add-on, including advanced encryption (BYOK).

Default (no ADPP): Zendesk-managed keys only; the report estimates Overall ~54.

Report confidence: Medium-high.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Zendesk's public documentation:

  • The opt-out process for Zendesk's generic cross-account ML training wasn't confirmed in the pages we read.
  • Generative AI and AI agents add many LLM and inference processors when used.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Zendesk data access, AI training, GDPR and residency

Can Zendesk read your support tickets?

Yes, Zendesk can read your tickets by design (with controls). Its BYOK covers user identity fields, not ticket content, and Zendesk trains cross-account classification models on Service Data. Support can only enter your account if an admin enables account assumption. VendorScore rates Zendesk 55/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Zendesk Suite Enterprise with the Advanced Data Privacy and Protection (ADPP) add-on, including advanced encryption (BYOK).

Is Zendesk data encrypted? What does Zendesk BYOK (advanced encryption) cover?

Zendesk encrypts traffic with TLS 1.2 or higher and says "Service Data is encrypted at rest in AWS using AES-256 key encryption." Advanced encryption (part of the ADPP add-on) uses your KMS (AWS KMS, Azure Key Vault, Google Cloud KMS or Thales CipherTrust), but only for user fields such as name, alias, signature, details, notes, email address and social identities. Ticket content stays on Zendesk-managed keys, and Zendesk warns: "Key rotation and revocation are not yet supported. If you rotate or revoke the keys, you might lose your encrypted data forever."

Can Zendesk support see my tickets?

Only if you let them into your account. Zendesk says "customers can allow Zendesk support to assume access to an account for a specific amount of time. By default, account assumption is deactivated and can only be activated by an account administrator." That gate covers support access; Zendesk's own systems still process ticket content, including for model training (see the next question).

Does Zendesk AI train on my data?

Yes, for Zendesk's own models. Zendesk's Trust Center says: "Zendesk uses Service Data to train its generic, cross-account machine learning models to be predictive and useful to multiple Zendesk customers." These are classification and clustering models. Zendesk says third-party LLM providers never use Zendesk customer data to train their models, and its AI Trust page says its own models "may be trained on customer data to the extent instructed by the customer". We couldn't confirm an opt-out path in public docs.

Is Zendesk GDPR compliant? Where is the Zendesk DPA?

VendorScore doesn't certify compliance; Zendesk publishes a DPA at https://www.zendesk.com/company/data-processing-agreement/. The DPA commits to updating the subprocessor list at least 30 days before a new subprocessor, with a 30-day objection window, and gives an audit right with 30 days' notice where law requires it.

Who are Zendesk's subprocessors?

Zendesk's Sub-processor Policy lists AWS and Google Cloud (QA, AI agents) for infrastructure; Cloudflare, Datadog, Sentry, Snowflake and Paragon for all services; generative AI providers Google, Baseten, ElevenLabs, Fireworks, Groq, OpenAI and Microsoft; plus Deepgram (voice transcripts), Twilio, SendGrid, MongoDB, Confluent, Aiven, Grafana and others. The list is published at https://support.zendesk.com/hc/en-us/articles/4408883061530-Sub-processor-Policy.

Can I keep Zendesk data in the EU (data residency)?

Yes, with the Data Center Location Add-on, which hosts Service Data in the EEA (or the US, UK, Japan or Australia). Without that entitlement Zendesk makes no residency commitment.

Compare Zendesk

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (zendesk.md), evidence dated 2026-10-07.