VendorScore · Customer support · Data-access posture
A plain-language answer from Zendesk's public Trust Center, Help Center and legal pages. Advanced encryption covers user fields; ticket conversations stay on Zendesk-managed keys.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, Zendesk can read your tickets by design (with controls). Its BYOK covers user identity fields, not ticket content, and Zendesk trains cross-account classification models on Service Data. Support can only enter your account if an admin enables account assumption.
Scored configuration: Zendesk Suite Enterprise with the Advanced Data Privacy and Protection (ADPP) add-on, including advanced encryption (BYOK).
Default (no ADPP): Zendesk-managed keys only; the report estimates Overall ~54.
Report confidence: Medium-high.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Zendesk's advanced encryption (BYOK) covers end-user identity fields such as name, email, signature and notes, and "Key rotation and revocation are not yet supported."
Evidence: About advanced encryptionZendesk support can only access your account if an admin turns on account assumption, which is off by default and can be time-limited.
Evidence: Zendesk secure-by-designOur report flags these gaps in Zendesk's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, Zendesk can read your tickets by design (with controls). Its BYOK covers user identity fields, not ticket content, and Zendesk trains cross-account classification models on Service Data. Support can only enter your account if an admin enables account assumption. VendorScore rates Zendesk 55/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Zendesk Suite Enterprise with the Advanced Data Privacy and Protection (ADPP) add-on, including advanced encryption (BYOK).
Zendesk encrypts traffic with TLS 1.2 or higher and says "Service Data is encrypted at rest in AWS using AES-256 key encryption." Advanced encryption (part of the ADPP add-on) uses your KMS (AWS KMS, Azure Key Vault, Google Cloud KMS or Thales CipherTrust), but only for user fields such as name, alias, signature, details, notes, email address and social identities. Ticket content stays on Zendesk-managed keys, and Zendesk warns: "Key rotation and revocation are not yet supported. If you rotate or revoke the keys, you might lose your encrypted data forever."
Only if you let them into your account. Zendesk says "customers can allow Zendesk support to assume access to an account for a specific amount of time. By default, account assumption is deactivated and can only be activated by an account administrator." That gate covers support access; Zendesk's own systems still process ticket content, including for model training (see the next question).
Yes, for Zendesk's own models. Zendesk's Trust Center says: "Zendesk uses Service Data to train its generic, cross-account machine learning models to be predictive and useful to multiple Zendesk customers." These are classification and clustering models. Zendesk says third-party LLM providers never use Zendesk customer data to train their models, and its AI Trust page says its own models "may be trained on customer data to the extent instructed by the customer". We couldn't confirm an opt-out path in public docs.
VendorScore doesn't certify compliance; Zendesk publishes a DPA at https://www.zendesk.com/company/data-processing-agreement/. The DPA commits to updating the subprocessor list at least 30 days before a new subprocessor, with a 30-day objection window, and gives an audit right with 30 days' notice where law requires it.
Zendesk's Sub-processor Policy lists AWS and Google Cloud (QA, AI agents) for infrastructure; Cloudflare, Datadog, Sentry, Snowflake and Paragon for all services; generative AI providers Google, Baseten, ElevenLabs, Fireworks, Groq, OpenAI and Microsoft; plus Deepgram (voice transcripts), Twilio, SendGrid, MongoDB, Confluent, Aiven, Grafana and others. The list is published at https://support.zendesk.com/hc/en-us/articles/4408883061530-Sub-processor-Policy.
Yes, with the Data Center Location Add-on, which hosts Service Data in the EEA (or the US, UK, Japan or Australia). Without that entitlement Zendesk makes no residency commitment.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (zendesk.md), evidence dated 2026-10-07.