ASA Labs Trust
Last updated: August 7, 2026

Security & Trust

ASA Labs builds Zendesk applications with a simple security principle: collect and retain as little customer data outside Zendesk as the product reasonably allows.

ASA Labs applications are designed to keep ticket content, workflow data, and application state within the customer’s Zendesk environment whenever practical. When an external service is required, data is limited to what is reasonably necessary to operate that service. Product-specific details are available in the Privacy Policy.

Our approach

Minimize data

Products are designed to avoid transmitting Zendesk ticket content to ASA Labs when a feature can operate within Zendesk.

Keep state close to Zendesk

Where practical, configuration, notes, tags, fields, workflow records, and other product state remain in the customer’s Zendesk account.

Limit telemetry

Applicable products use limited operational telemetry designed around product usage and configuration rather than customer conversations.

Protect access

ASA Labs uses access controls, credential protection, and managed security controls designed to restrict access to systems and services.

Data handling

Data handling varies by product, but ASA Labs starts from the same principle: only use the information needed for the feature being provided.

  • Zendesk-native applications are designed to keep ticket content and workflow data in the customer’s Zendesk environment while using limited operational telemetry where applicable.
  • Rollout Control maintains limited external connection information needed to authenticate and operate its Zendesk integration. Rollout configuration and ticket assignment records remain in Zendesk.
  • Free browser-based admin tools process uploaded or pasted Zendesk configuration locally in the browser unless a tool explicitly states otherwise.

Detailed product-by-product disclosures, including what may be accessed, stored, or retained, are maintained in the Privacy Policy.

Infrastructure and access

ASA Labs uses managed hosting, database, security, authentication, email, analytics, and payment services where needed to operate the website and applications. Access to systems and service credentials is limited to what is needed to operate, maintain, and support the services.

Customers remain responsible for their own Zendesk administrator access, user permissions, integrations, application configuration, and internal security policies.

Transport, retention, and deletion

ASA Labs relies on HTTPS/TLS for data transmitted between customers, Zendesk, ASA Labs-hosted services, and infrastructure providers. Externally stored information is retained only as reasonably necessary to operate, secure, support, and improve the applicable service or meet legitimate business and legal needs.

Records written to Zendesk remain subject to the customer’s Zendesk retention settings. Where an ASA Labs service maintains an external connection record, customers may use available product controls or contact ASA Labs regarding applicable deletion requests.

Artificial intelligence and customer data

ASA Labs does not use Zendesk customer or ticket data to train public or third-party artificial intelligence models. If a future feature materially changes how customer data is handled, the applicable disclosures will be updated.

Compliance posture

ASA Labs does not currently represent that it holds an independent SOC 2 or ISO 27001 certification. Customers should evaluate each application against their own legal, security, privacy, and compliance requirements.

Security reports and responsible disclosure

If you believe you have found a vulnerability or security issue in an ASA Labs website or application, please report it privately and include enough detail to reproduce or investigate the issue.

Security: security@asa-labs.com

Please do not publicly disclose a suspected vulnerability before ASA Labs has had a reasonable opportunity to investigate and address it.

Questions about security

For security or data-handling questions related to an evaluation, email security@asa-labs.com. You can also review the Privacy Policy.