Help Desk Security & Compliance Guide
Your help desk quietly becomes the biggest store of customer personal data you own — names, emails, order histories, screenshots, sometimes health or payment details customers paste in themselves. This is the plain-English guide to keeping it safe and legal: what the security badges actually mean, what to verify before you sign, and which of the help desks we rank document each protection. No jargon left unexplained.
Why this is the criterion buyers underweight
Most help desk shopping is about speed, automations and price. Security feels like a box already ticked — every vendor's site says enterprise-grade security, so people move on. That is exactly the mistake. Your support inbox accumulates more customer personal data than almost any other system in the company, and customers cheerfully paste things into tickets you would never dream of storing — full card numbers, medical details, passwords. A single breach or a mishandled deletion request can cost far more than years of subscription savings. Security and compliance is one of the five weighted criteria in our methodology, and this guide is where we make it visible.
The key idea to hold onto is that compliance is shared. The vendor gives you a certified, well-built platform; you are responsible for how you set it up and who you let read the tickets. So your job as a buyer is two-part: verify what the vendor genuinely provides, then configure your side properly. We will take each in turn, defining every term as we go.
What to verify before you buy
SOC 2 is a report, common in the United States, where an independent firm checks that the security practices a vendor claims are real and working. Ask specifically for the Type II report — it covers a stretch of months, not a single inspection day, so it is far harder to stage. Your help desk stores every customer conversation, so if a vendor cannot share a report under a non-disclosure agreement, treat that as a warning.
ISO 27001 is a globally recognised certificate showing the vendor runs a formal, audited system for managing information security — policies, risk reviews, staff training, the lot. Where SOC 2 is the American reference point, ISO 27001 is the international one. The strongest help desks hold both; the absence of either is a real concern for a tool holding your customers' data.
GDPR is the European data-protection law that applies if you hold data on people in the EU or UK — and support inboxes are full of it. The practical thing to get is a DPA, a Data Processing Agreement: the contract where the vendor commits to process that data lawfully, host it in the right region, and help you honour requests such as deleting all of a customer's past tickets. Confirm EU-region hosting if your customers are European.
HIPAA is a US healthcare law covering PHI — Protected Health Information, meaning data that identifies a patient and relates to their health. If your help desk supports a medical or dental practice, customers will paste exactly that into a ticket. To hold it lawfully you need the vendor to sign a BAA, a Business Associate Agreement in which it shares legal responsibility for the data. This is the sharpest dividing line here: several excellent help desks will not sign one. Never assume — confirm it in writing for your exact plan.
PCI DSS is the payment-card industry's security standard. You may think it does not apply to a help desk — until a customer types their full card number into a ticket to sort out a charge. The safe practice is to make sure that never lands in your inbox: pick a tool that can redact card numbers automatically, and never ask customers to send card details by email or chat. This matters most for ecommerce and retail desks.
Two basics belong on every shortlist. Encryption in transit and at rest simply means your data is scrambled both while travelling to the help desk and while sitting on its servers, so a thief gets gibberish. And role-based agent permissions with single sign-on and two-factor login let you control exactly who can read which tickets. The most common help-desk breach is not a hacker — it is an over-permissioned or compromised agent account, so this is where the real protection lives.
The compliance matrix
Here is where each of the seven tools in our help desk ranking stands on the four contracts and certificates that matter most, verified as of June 2026. Read the HIPAA column especially carefully: a tick means a BAA is available, a tilde means only on a specific higher edition, add-on or on request, and a dash means no BAA — so it cannot lawfully hold patient health data. Editions and policies change often; always confirm the current position in writing for your exact plan.
✓ available · ∼ on a specific edition, add-on or request · — not offered. Verified June 2026 from vendor compliance documentation; confirm the current position for your exact plan before relying on it.
What to look for, and what to walk away from
Both are independent proofs that a vendor takes security seriously. SOC 2 is an audit report, mostly used in the United States, where an outside firm checks that the controls a vendor claims are actually in place — ask for the Type II report, which covers a period of months rather than a single day. ISO 27001 is an international certificate showing the vendor runs a formal information-security management system. For a help desk holding every customer conversation, seeing both is reassuring; seeing neither is a red flag.
As of mid-2026: Zoho Desk and Help Scout will sign a BAA; Freshdesk (on Enterprise), Zendesk (through its Advanced Compliance add-on) and Intercom (on enterprise plans) offer one on a specific higher tier or add-on; HubSpot Service Hub and Gorgias do not sign a BAA, so they cannot lawfully hold patient health information. Editions and policies change, so always get the current position in writing for your exact plan before putting any PHI in a ticket.
Then HIPAA is not your concern, but GDPR and PCI DSS are. GDPR governs your customers' personal data and your ability to delete it on request; PCI DSS covers what happens if someone pastes a card number into a ticket. The practical rules: choose a tool that can redact card numbers automatically, never ask customers to send payment details by email or chat, and confirm you can export and delete a customer's full history. Ecommerce-focused desks like Gorgias are built around exactly this.
No, and this is the most expensive misunderstanding. Compliance is shared. The vendor provides the certified platform, encryption, a Data Processing Agreement and region hosting; you are responsible for how you configure it — which agents can see which tickets, how long you keep old conversations, how you redact sensitive data, and how you handle deletion requests. A compliant help desk set up carelessly, with every agent able to read everything, is still a breach waiting to happen.
One email when the rankings move. The shortlist, the tradeoffs, the compliance changes. No filler.