Is Zendesk AI SOC 2 compliant?
YesZendesk · Customer support
Yes. Zendesk holds a SOC 2 report covering Zendesk AI, which gives independent assurance over its security controls.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- SOC 2 report
- Confirmed
- Zendesk reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
- ISO 27001
- Confirmed
- Zendesk also reports ISO/IEC 27001 certification.
- Default data training
- Opt-out required
- Zendesk trains AI functionality on Service Data by default (most customers instruct Zendesk to train); opt out by contacting support to exclude your subdomains. Integrated third-party LLMs never train on customer data.
- Business-tier training
- Opt-out required
- Suite Enterprise plus the Advanced Compliance (HIPAA) and Data Center Location (residency) add-ons is the business tier recorded for this profile.
Practical risk: Zendesk holds SOC 2 Type II and ISO 27001 and 42001 and will sign a BAA via a paid add-on, but it trains its own AI on Service Data by default; you must contact support to opt out, and EU residency and HIPAA are both paid add-ons.
How to make a decision
Check the precise account tier, written contract and intended data before approving Zendesk AI. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Zendesk AI
Is Zendesk AI HIPAA compliant?Is Zendesk AI GDPR compliant?Is Zendesk AI ISO 27001 certified?Does Zendesk AI train on your data?
See the full Zendesk AI risk profile, with every data-handling fact and its source, or browse all rated AI tools.