Zendesk hosts service data primarily in AWS data centers worldwide. These data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 2 compliant. Zendesk also offers data locality choices in certain regions to meet specific customer needs.
Zendesk is PCI DSS compliant as a merchant, but not as a billing system. As a merchant, Zendesk complies with PCI DSS standards. However, as a cloud-based service provider, Zendesk does not engage in the payment card processing lifecycle. While…
Zendesk uses a PCI Compliant Ticket Field to redact card numbers. This feature allows businesses to enter a Personal Account Number (PAN) into a custom ticket field, which is then redacted to the last 4 digits before submission to the Zendesk…
Automatic Redaction helps manage PCI responsibilities by redacting card data. This feature uses a Luhn check algorithm to identify and truncate card numbers to the first 6 and last 4 characters. It masks the data in the UI and redacts it from logs…
The PCI Compliant Ticket Field redacts card data before it enters Zendesk, while Automatic Redaction does so after. The PCI Compliant Ticket Field is audited and certified as PCI compliant, handling card numbers before they enter the platform….
Zendesk employs industry-standard security controls and encryption. All communications with Zendesk UI and APIs are encrypted using HTTPS/TLS, and service data is encrypted at rest in AWS using AES-256 key encryption. This ensures that data is…
To enable PCI compliance, activate the credit card custom field. This allows your Zendesk instance to benefit from the Attestation of Compliance (AoC) and ensures a PCI compliant environment. Without this activation, your instance may not be fully…
Zendesk uses AWS security services and Cloudflare for network protection. The network is safeguarded through key AWS security services, integration with Cloudflare edge protection networks, regular audits, and network intelligence technologies to…