Minimize data
Products are designed to avoid transmitting Zendesk ticket content to ASA Labs when a feature can operate within Zendesk.
ASA Labs builds Zendesk applications with a simple security principle: collect and retain as little customer data outside Zendesk as the product reasonably allows.
Products are designed to avoid transmitting Zendesk ticket content to ASA Labs when a feature can operate within Zendesk.
Where practical, configuration, notes, tags, fields, workflow records, and other product state remain in the customer’s Zendesk account.
Applicable products use limited operational telemetry designed around product usage and configuration rather than customer conversations.
ASA Labs uses access controls, credential protection, and managed security controls designed to restrict access to systems and services.
Data handling varies by product, but ASA Labs starts from the same principle: only use the information needed for the feature being provided.
Detailed product-by-product disclosures, including what may be accessed, stored, or retained, are maintained in the Privacy Policy.
ASA Labs uses managed hosting, database, security, authentication, email, analytics, and payment services where needed to operate the website and applications. Access to systems and service credentials is limited to what is needed to operate, maintain, and support the services.
Customers remain responsible for their own Zendesk administrator access, user permissions, integrations, application configuration, and internal security policies.
ASA Labs relies on HTTPS/TLS for data transmitted between customers, Zendesk, ASA Labs-hosted services, and infrastructure providers. Externally stored information is retained only as reasonably necessary to operate, secure, support, and improve the applicable service or meet legitimate business and legal needs.
Records written to Zendesk remain subject to the customer’s Zendesk retention settings. Where an ASA Labs service maintains an external connection record, customers may use available product controls or contact ASA Labs regarding applicable deletion requests.
ASA Labs does not use Zendesk customer or ticket data to train public or third-party artificial intelligence models. If a future feature materially changes how customer data is handled, the applicable disclosures will be updated.
ASA Labs does not currently represent that it holds an independent SOC 2 or ISO 27001 certification. Customers should evaluate each application against their own legal, security, privacy, and compliance requirements.
If you believe you have found a vulnerability or security issue in an ASA Labs website or application, please report it privately and include enough detail to reproduce or investigate the issue.
Security: security@asa-labs.com
Please do not publicly disclose a suspected vulnerability before ASA Labs has had a reasonable opportunity to investigate and address it.
For security or data-handling questions related to an evaluation, email security@asa-labs.com. You can also review the Privacy Policy.